Hi, it seems that tcptrace works for this task:
$ tcptrace -e testcase.pcap 1 arg remaining, starting with 'testcase.pcap' Ostermann's tcptrace -- version 6.6.7 -- Thu Nov 4, 2004 18 packets seen, 18 TCP packets traced elapsed wallclock time: 0:00:00.004153, 4334 pkts/sec analyzed trace file elapsed time: 0:00:25.006063 TCP connection info: 1: localhost:39885 - localhost:3000 (a2b) 5> 4< (complete) 2: localhost:36781 - localhost:3000 (c2d) 5> 4< (complete) $ head *.dat ==> a2b_contents.dat <== ipv4 traffic ==> c2d_contents.dat <== ipv6 traffic -Timo -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org