Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Other <strong>use</strong>ful expressions are:<br />
Field Property Value<br />
IP address (source or destination) ip.addr IP address<br />
Source IP address ip.src IP address<br />
Destination IP address ip.dst IP Address<br />
TCP port (source or destination) tcp.port Port number (0-65535)<br />
TCP source port tcp.srcport Port number (0-65535)<br />
TCP destination port tcp.dstport Port number (0-65535)<br />
UDP port (source or destination) udp.port Port number (0-65535)<br />
UDP source port udp.srcport Port number (0-65535)<br />
UDP destination port udp.dstport Port number (0-65535)<br />
<strong>fw</strong> moni<strong>to</strong>r direction <strong>fw</strong>1.direction “i”, “I”, “o” or “O”<br />
<strong>fw</strong> moni<strong>to</strong>r interface <strong>fw</strong>1.interface An Interface name (e.g. “eth0”)<br />
Figure 67: Ethereal – Useful filter properties<br />
! Ethereal filters require no special syntax <strong>to</strong> check whether an IP address belongs <strong>to</strong> a specific<br />
subnet. Instead you can <strong>use</strong> an IP address with Classless Inter Domain Routing (CIDR) notation<br />
(e.g. 192.168.10.26/24) anywhere instead of a normal IP address. To check whether a packet is<br />
sent from or sent <strong>to</strong> a specific network (192.168.10.26/24) you can <strong>use</strong> the following filter:<br />
ip.addr eq 192.168.10.26/24<br />
You can find a list with all known properties under Help/Help/Display Filters.<br />
<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 53 of 70<br />
Revision: 1.01