在练习写过滤表达式但是在网上看到教程这么些 我粘到我的 fliter 里面就不能使用不知如何修改
Capture only traffic to or from IP address 172.18.5.4:
host 172.18.5.4
Capture non-HTTP and non-SMTP traffic on your server (both are equivalent):
host
www.example.com and not (port 80 or port 25)
host
www.example.com and not port 80 and not port 25
Capture except all ARP and DNS traffic:
port not 53 and not arp
Capture traffic within a range of ports
(tcp[2:2] > 1500 and tcp[2:2] < 1550) or (tcp[4:2] > 1500 and tcp[4:2] < 1550)
or, with newer versions of libpcap (0.9.1 and later):
tcp portrange 1501-1549
Capture only Ethernet type EAPOL:
ether proto 0x888e
Reject ethernet frames towards the Link Layer Discovery Protocol Multicast group:
not ether dst 01:80:c2:00:00:0e
谢谢