wireshark过滤器使用


1. 抓包过滤器
1. tcp src port 443
udp port 20000
udp dst port 20000
udp src port 10000
udp dst port 20000 and src port 10000
2. not arp
3. port 80
4. src 192.168.1.121 and port 233
5.
protocols: ether, fddi, ip, arp, rarp, decnet, lat, tcp
direction: src, dst, src and dst, src or dst
hosts: net port host portrange
logical:not and or
2.展示过滤器
tcp.port == 6064
!arp
ip.addr == 172.16.0.162
ip.dst ==172.16.0.162
ip.src == 114.80.30.35
(ip.dst ==172.16.0.162) && (ip.src != 116.62.198.96) && (ip.src != 61.151.180.236) || !(ip.src != 114.80.30.35)