I tried tcpdump -i rl0 src host 218.166.163.180 -w /usr/tcpdump.data tcpdump -i rl0 host 218.166.163.180 -w /usr/tcpdump.data tcpdump -i rl0 src ip 218.166.163.180 -w /usr/tcpdump.data
but got syntax error msg with no hint of what was wrong If I remove the -w stuff it works. Meaning it prints to the screen. But I want to write to file Can you help me out here on the syntax error? One other thing. When does tcpdump get access to the packet? My firewall has a block log rule for that ip address. Does tcpdump see the packet before ipfilter ipnat does? _______________________________________________ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to "[EMAIL PROTECTED]"