I would do tcpdump -w capture_file -s0 -i interface
the -s0 makes sure the packets are not cut in size... On 18.01.2007, at 02:38, Sebastien Tandel wrote: > basically, > > tcpdump -w capture_file -i interface_name > > tshark -r capture_file > > > but the man pages should be of great help for further information. > > Regards, > > Sebastien Tandel > > ARAMBULO, Norman R. wrote: >> Hi, has anyone tried using tcpdump or dumpcap to capture packets on a >> GigE interface, we are not sure how tcpdump works could somebody help >> me with this. >> >> Pls expain how can we use the tcpdump to capture file and later read >> it using Tshark or Tethereal. Thanks >> >> >> >> >> >> >> >> "Reality is merely an illusion, albeit a very persistent one." >> >> >> -- Albert Einstein >> >> Norman R. Arambulo >> National Fraud Management Division >> Internal Audit & Fraud Risk Management Group >> >> Tel. No : 632-8889119/22 >> >> Fax No.: 632-8444889 >> >> >> >> >> >> --------------------------------------------------------------------- >> --- >> >> _______________________________________________ >> Wireshark-users mailing list >> [email protected] >> http://www.wireshark.org/mailman/listinfo/wireshark-users >> > > _______________________________________________ > Wireshark-users mailing list > [email protected] > http://www.wireshark.org/mailman/listinfo/wireshark-users _______________________________________________ Wireshark-users mailing list [email protected] http://www.wireshark.org/mailman/listinfo/wireshark-users
