Wireshark mailing list archives

Re: Capture filter question


From: David Alanis <canito () dalan us>
Date: Sat, 05 Nov 2011 20:54:25 -0500

Quoting David Alanis <canito () dalan us>:

Quoting Marco Zuppone <msz () msz it>:

Hello,

I have a question about capture filters.
I noticed that the basic capture filter predefined in Wireshark to do not capture arp and DNS requests is defined in this way:
not arp and port not 53

What is the difference with: not arp and not port 53?

Thanks in advance
Marco - StockTrader
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request () wireshark org?subject=unsubscribe



Sorry, I think I jumped the gun on my previous e-mail. I know that 'not arp' will filter out the address resolution protocol. 'not port 53' will simply discard communication over port 53.

Is there something more specific that I am not understanding about these two capture filters?

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: