Why do operators run tcpdump with `-n` during an incident, and what does tcpdump do without it?
answer
- names cost lookups
- the capture makes its own traffic
- ports become service names too
- one n is enough
basics
~20 sWithout -n, tcpdump converts addresses to host names with reverse DNS lookups and port numbers to service names. That slows or stalls output, adds DNS traffic, and hides the numbers you need. One -n turns off both.
solid answer
~50 sBy default tcpdump turns values into names: IP addresses into host names through reverse lookups, port numbers into service names such as `https`, and other identifiers into names where it has a table. During an incident that is the wrong default. Each new address triggers a lookup, so output lags or stalls — badly when DNS is the thing that is broken — and the lookups are extra traffic from the host you are investigating. Names also hide evidence: `https` does not tell you the port was 443, and a stale reverse record can name the wrong machine. `-n` turns all of it off; the tcpdump manual describes it as not converting host addresses, port numbers and so on to names, so a second `n` changes nothing further in tcpdump 4.99. `-N` is different: it only drops the domain part of names it still looks up.
go deeper
Recall that -n keeps addresses and ports numeric, and that without it tcpdump looks up names for every new address it prints.
Explain the costs of name conversion — lookup delay, DNS traffic from the host, misleading names — and why one -n covers ports as well.
Build captures that survive a DNS outage and correlate with logs: numeric output, dated timestamps, and payload dumps only where the protocol is clear text.
Standardise capture command lines in runbooks so evidence from different engineers is numeric, dated and comparable without post-processing.
## What tcpdump does by default Without options, tcpdump tries to make its output readable to a human by converting numbers to names: - **IP addresses** become host names through a reverse lookup — for IPv4 and IPv6 alike. - **Port numbers** become service names from the system's services list: `443` prints as `https`, `22` as `ssh`. - **Ethernet addresses**, when `-e` is used, can be shown with names from the system's ethers table. - **Protocol numbers** are shown by name where tcpdump knows one. The same line, with and without `-n`: ``` IP client-17.example.internal.51514 > api.example.com.https: Flags [S], seq 1584207323, ... IP 192.0.2.10.51514 > 198.51.100.20.443: Flags [S], seq 1584207323, ... ``` ## Why that default hurts during an incident 1. **Latency and stalls.** Each new address costs a lookup before the line can be printed. On a busy capture the output trails reality; when the resolver is slow or down, output can freeze while tcpdump waits. 2. **Traffic of its own.** The lookups are DNS queries from the very host you are watching. If the capture expression matches them, they appear in the capture, interleaved with the evidence. 3. **Hidden numbers.** A service name is a guess based on the port number, not proof of the protocol. `https` on a line only means port 443; a service on an unusual port may print as an unrelated name or as a bare number. 4. **Misleading names.** A reverse record can be stale, missing or deliberately vague, so a name in the output can point at the wrong machine. ## What the options actually do | Option | Effect in tcpdump 4.99 | |---|---| | `-n` | no conversion of host addresses, port numbers or other values to names | | `-nn` | the same as `-n`; the second `n` adds nothing | | `-N` | still resolves names, but prints only the first label (`nic`, not `nic.ddn.mil`) | | `-f` | prints foreign IPv4 addresses numerically while still resolving local ones | A common belief is that `-n` covers only addresses and `-nn` is needed for ports. In tcpdump 4.99 that is not how the option works: one `-n` skips building the services, ethers and protocol tables entirely, and the code only checks whether the option was given, not how many times. Typing `-nn` is a harmless habit. ## The other output options you add next Once the output is numeric, a few more options shape a line for incident work: - **`-tttt`** prints the date and time of day on every line. The default timestamp is the time of day without a date; `-tt` prints seconds since 1970, `-ttt` the delta from the previous line, `-ttttt` the delta from the first. Dated timestamps make it easy to line up packets with application logs. - **`-v` / `-vv`** add IP header detail such as `ttl`, `id` and `length`, and switch on checksum checks; `-vv` decodes some protocols further. - **`-e`** adds the link-level header, so on Ethernet you see source and destination MAC addresses and the EtherType — useful when two hosts claim the same IP address. - **`-A`** prints each packet's payload as ASCII, and **`-X`** as hex and ASCII side by side. They help with clear-text protocols; on an encrypted connection they show only ciphertext. With `-e`, the same SYN reads: ``` 10:42:07.118204 02:00:00:00:00:0a > 02:00:00:00:00:01, ethertype IPv4 (0x0800), length 74: 192.0.2.10.51514 > 198.51.100.20.443: Flags [S], seq 1584207323, ... ``` The MAC addresses come first, then the EtherType and the frame length, and the `IP` marker disappears because the link-layer header now says what follows. The frame length, 74, is the whole frame including the 14-byte Ethernet header, while the `length` at the end of the TCP part still counts only payload bytes. ## The habit worth forming Start every interactive capture with `-n`, and add a timestamp format that matches the logs you will compare against. Names can always be looked up afterwards for the handful of addresses that matter, outside the capture, without slowing it or adding traffic to it.
- Is -nn different from -n in tcpdump 4.99?No. A single `-n` already stops tcpdump converting host addresses, port numbers and other values to names; the code checks only whether the option was given. Typing `-nn` is a harmless habit, but teaching that ports need a second `n` is wrong for this release.
- What does tcpdump's -N do, and can it replace -n?`-N` prints host names without their domain qualification — `nic` instead of `nic.ddn.mil`. It still performs the lookups, so it keeps the delay and the extra DNS traffic. It shortens lines; it does not make output numeric.
- Which tcpdump option prints payload bytes, and when is it useless?`-A` prints each packet's payload as ASCII and `-X` prints hex and ASCII side by side. Both help with clear-text protocols such as plain HTTP; on a TLS connection they show only ciphertext, so they add volume without adding evidence.
saying these in an interview costs you the question
- -n only stops host name lookups; ports need -nn.
- Without -n, tcpdump generates no network traffic of its own.
- -N is just another spelling of -n.
- A service name like https in the output proves the traffic is HTTPS.
- The default timestamp includes the date.