On Nov 13, 2012, at 12:34 AM, Guy Harris <[email protected]> wrote:

> "proto {XXX}" is short for "ip proto {XXX} or ip6 proto {XXX}" (or just "ip 
> proto {XXX}" in versions of libpcap that don't support IPv6), which means the 
> argument to "proto" must be a protocol running atop IP, e.g. "proto tcp" or 
> "proto udp".  I'll fix the pcap-filter man page to document that.

I've checked that change into the trunk and 1.3 branch of the tcpdump.org Git 
repository for libpcap.

--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to