15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Other <strong>use</strong>ful expressions are:<br />

Field Property Value<br />

IP address (source or destination) ip.addr IP address<br />

Source IP address ip.src IP address<br />

Destination IP address ip.dst IP Address<br />

TCP port (source or destination) tcp.port Port number (0-65535)<br />

TCP source port tcp.srcport Port number (0-65535)<br />

TCP destination port tcp.dstport Port number (0-65535)<br />

UDP port (source or destination) udp.port Port number (0-65535)<br />

UDP source port udp.srcport Port number (0-65535)<br />

UDP destination port udp.dstport Port number (0-65535)<br />

<strong>fw</strong> moni<strong>to</strong>r direction <strong>fw</strong>1.direction “i”, “I”, “o” or “O”<br />

<strong>fw</strong> moni<strong>to</strong>r interface <strong>fw</strong>1.interface An Interface name (e.g. “eth0”)<br />

Figure 67: Ethereal – Useful filter properties<br />

! Ethereal filters require no special syntax <strong>to</strong> check whether an IP address belongs <strong>to</strong> a specific<br />

subnet. Instead you can <strong>use</strong> an IP address with Classless Inter Domain Routing (CIDR) notation<br />

(e.g. 192.168.10.26/24) anywhere instead of a normal IP address. To check whether a packet is<br />

sent from or sent <strong>to</strong> a specific network (192.168.10.26/24) you can <strong>use</strong> the following filter:<br />

ip.addr eq 192.168.10.26/24<br />

You can find a list with all known properties under Help/Help/Display Filters.<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 53 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!