tcpdump mailing list archives
pcap question
From: "subramoni padmanabhan" <smoni77 () hotmail com>
Date: Wed, 08 Jan 2003 22:17:20 -0500
hi,I have a problem capturing packets using pcap. My application requires me to capture RAW(packets sent from a RAW socket whose IP header has been constructed by the sending application) packets with a particular protocol number. What might be the filter expression be for such a capture to be effected? I tried "ip[10]=IPPROTO_MYESP" where IPPROTO_MYESP is a user-defined protocol but this doesn't seem to work. Any ideas will be greatly appreciated. Thanks.
Subramoni Padmanabhan G-126, 700 woodland avenue Lexington, Kentucky 40508 Phone : 859 323 9405 _________________________________________________________________MSN 8: advanced junk mail protection and 2 months FREE*. http://join.msn.com/?page=features/junkmail
- This is the TCPDUMP workers list. It is archived at http://www.tcpdump.org/lists/workers/index.html To unsubscribe use mailto:tcpdump-workers-request () tcpdump org?body=unsubscribe
Current thread:
- pcap question subramoni padmanabhan (Jan 08)
- Re: pcap question Guy Harris (Jan 08)
- <Possible follow-ups>
- pcap question subramoni padmanabhan (Feb 20)