On Nov 13, 2012, at 12:34 AM, Guy Harris <[email protected]> wrote: > "proto {XXX}" is short for "ip proto {XXX} or ip6 proto {XXX}" (or just "ip > proto {XXX}" in versions of libpcap that don't support IPv6), which means the > argument to "proto" must be a protocol running atop IP, e.g. "proto tcp" or > "proto udp". I'll fix the pcap-filter man page to document that.
I've checked that change into the trunk and 1.3 branch of the tcpdump.org Git repository for libpcap. -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

