Linux - NetworkingThis forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
I don't agree with that conclusion at all. Read the manpages for tcpdump(1).
Code:
When tcpdump finishes capturing packets, it will report counts of:
packets ``captured'' (this is the number of packets that tcpdump
has received and processed);
packets ``received by filter'' (the meaning of this depends on
the OS on which you're running tcpdump, and possibly on the way
the OS was configured - if a filter was specified on the command
line, on some OSes it counts packets regardless of whether they
were matched by the filter expression and, even if they were
matched by the filter expression, regardless of whether tcpdump
has read and processed them yet, on other OSes it counts only
packets that were matched by the filter expression regardless of
whether tcpdump has read and processed them yet, and on other
OSes it counts only packets that were matched by the filter
expression and were processed by tcpdump);
packets ``dropped by kernel'' (this is the number of packets
that were dropped, due to a lack of buffer space, by the packet
capture mechanism in the OS on which tcpdump is running, if the
OS reports that information to applications; if not, it will be
reported as 0).
To test packet filtering rules, use nmap / netcat / hping or other security tools that will allow you to send packets appropriate for your testing.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.