> Well, you can open your pcap file with Wireshark (ethereal), select > the packets you want using the filter and saving them using the > standard "save as" option. > > Is it enough or you need something more "scriptable" that can be done > from the command-line?
Command line would be preferred. But I'm also wondering if maybe what I wanted to do here was misunderstood. I don't want to simply pick all the GRE packets and save those in pcap format. I want to pick the GRE packets and save them *without* the outer IP + GRE header, in pcap format. Steinar Haug, Nethelp consulting, [EMAIL PROTECTED] - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
