I would be easier to accomplish this using wireshark.  Simply open the 
pcap, filter on one direction save the displayed packets and repeat for 
the other side.

On 05/25/2012 04:26 AM, Jaime Nebrera wrote:
>     Hi all,
>
>     This is my first post to the list so please be gentle :D
>
>     I have a pcap file including both directions traffic from a bunch of
> servers and clients. Im aware I can create a cache file of such pcap in
> order to "split" it in multiple ways. Actually I have already done so.
>
>     The problem is, the final result is still a pcap file and a cache
> file, that yes, tcpreplay fully understands but maybe not other tools.
>
>     From this pcap + cache combo I would like to "create" two distinct
> pcap files, one with all client ->  server packets, the other with all
> server ->  client packets
>
>     How can I do this? Is it possible?
>
>     Very thankful in advance. Regards
>

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Tcpreplay-users mailing list
Tcpreplay-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/tcpreplay-users
Support Information: http://tcpreplay.synfin.net/trac/wiki/Support

Reply via email to