skip to content

tcpdump

tcpdump is the capture tool already on the server: open an interface, filter in the kernel with a pcap expression, and write a pcap or read its terse lines. Interviewers expect a filter from memory.

on this pageshow

explore

questions

18

On a Linux server, how do you use tcpdump to choose the right interface and save traffic for later analysis in Wireshark?

level: juniorimportance: must knowfreq 38%

answer

  1. list devices before listening
  2. default interface is a guess
  3. raw packets, not printed text
  4. the any device is cooked

basics

~20 s

List capture devices with tcpdump -D, capture with tcpdump -i eth0 -w /var/tmp/web.pcap and a filter, stop with -c or Ctrl-C, then read the file with -r or Wireshark. Use -i any only to find the interface.

solid answer

~40 s

`tcpdump -D` lists every device libpcap can capture on, numbered, and `-i` takes the name or the number. Without `-i`, tcpdump 4.99 picks the lowest-numbered interface that is up, excluding loopback, which on a multi-homed host can be the wrong NIC. `-w /var/tmp/web.pcap` saves the raw packets in pcap format instead of printing them; redirecting printed output with `>` only saves text that Wireshark cannot open. Stop with `-c 5000` or Ctrl-C, put the filter expression last, and read the file back with `tcpdump -r` (no root needed) or Wireshark. `-i any` captures all regular interfaces on Linux, but with a cooked pseudo-header instead of the Ethernet header and never in promiscuous mode.

code

bash · 3 lines
bash
tcpdump -D
sudo tcpdump -i eth0 -c 5000 -w /var/tmp/web-443.pcap 'tcp port 443'
tcpdump -n -r /var/tmp/web-443.pcap | head -20

go deeper

for a junior

Recall the four moves: -D to list devices, -i to choose one, -w to save raw packets, -r to read them back. Say clearly that redirected text is not a capture file.

for a middle

Explain how tcpdump picks an interface when -i is missing and what the any pseudo-interface changes: a cooked header, no promiscuous mode, possible duplicates across interfaces.

for a senior

Show the production habits: name the interface on multi-homed hosts, bound the capture with -c or a filter, check the drop counters before trusting the file, and treat captures as sensitive data.

for a principal

Discuss who may capture on production hosts, where capture files may live and for how long, and how a team standardises a capture runbook so evidence is consistent across incidents.

## What a first capture has to decide A packet capture with **tcpdump** settles three things before it starts: which **capture device** to listen on, where the packets go (decoded and printed to the terminal, or saved raw to a **savefile**), and when to stop. Getting one of them wrong gives the classic first-capture failures: a file Wireshark refuses to open, a capture of the wrong network card, or a capture that runs until the disk is full. ## Choosing the interface - `tcpdump -D` (long form `--list-interfaces`) prints every device libpcap can capture on, each with a number, a name and often a description. Either the number or the name can be passed to `-i`. - Without `-i`, tcpdump 4.99 searches the interface list for the **lowest-numbered interface that is up, excluding loopback**. On a host with a management NIC, a bond, VLAN sub-interfaces or container bridges, that guess is easily the wrong one, so name the interface. - `-i any` is a **pseudo-interface** on Linux (and recent macOS and Solaris) that captures from all regular network interfaces at once. It is the right first move when you do not know which interface carries a flow, because each printed line names the interface it was seen on. - `-Q in`, `-Q out` or `-Q inout` (long form `--direction`) keeps only received or only sent packets, on platforms that support it. | | Named interface (`-i eth0`) | `-i any` on Linux | |---|---|---| | Link-layer header | the real Ethernet header, both MAC addresses | a cooked pseudo-header: packet type, interface, one source link-layer address | | Promiscuous mode | requested by default; `-p` turns the request off | never | | Same packet seen twice | no | possible when it crosses two interfaces | | Best for | a known path, MAC-level questions | finding which interface carries the flow | On Linux the cooked header (link type `LINUX_SLL2`, the default for `any` since tcpdump 4.99.0 where libpcap supports it) records whether a packet was addressed to this host, broadcast, multicast, addressed to another host or sent by this host, and printed lines show the interface name with `In` or `Out`. A packet that crosses a bridge and its member port, or a VLAN sub-interface and its parent, can be captured once on each. ## Promiscuous mode and `-p` By default tcpdump asks for **promiscuous mode** on a named interface, so the NIC passes up frames that are not addressed to it. On a switched network that rarely adds much: the switch delivers this host's traffic plus broadcast and flooded frames unless a mirror port feeds the interface, and getting other hosts' traffic to the capture point is a separate subject. `-p` (`--no-promiscuous-mode`) tells tcpdump not to enable it. The man page warns that the interface may already be promiscuous for another reason, so `-p` is not a filter meaning "only my traffic". ## Writing and reading a file - `-w file` writes the **raw packets** in pcap format instead of decoding and printing them; `-w -` writes them to standard output. - Redirecting printed output with `>` saves **text**. Calling it `.pcap` changes nothing: readers recognise a capture file by the magic number in its header, not by its extension (tcpdump adds none, though the man page recommends `.pcap`). - `-r file` reads a savefile back. It needs **no special privileges**, unlike opening a live device. - `-c count` exits after that many packets. Without `-c`, tcpdump runs until it receives SIGINT (Ctrl-C) or SIGTERM. - On exit tcpdump reports packets captured, received by filter and dropped by kernel; a non-zero drop count means the file has gaps the network did not cause. ## A safe first capture, step by step 1. Run `tcpdump -D` and identify the interface that carries the traffic, or watch `-i any` for a few seconds to see which interface the flow uses. 2. Capture to a disk with room: `sudo tcpdump -i eth0 -c 5000 -w /var/tmp/web-443.pcap 'tcp port 443'`. The filter expression always comes last, quoted for the shell. 3. Read the summary for drops, then copy the file off the host and open it in Wireshark, or read it with `tcpdump -r`. 4. Delete the capture when you are done: payloads can hold credentials and personal data.

  • Why can't Wireshark open the file produced by `tcpdump -i eth0 > capture.pcap`?
    Without `-w`, tcpdump decodes each packet and prints a text line to standard output, so the redirect saved text with a `.pcap` name. Capture readers identify a pcap file by the magic number in its header, not the extension, so Wireshark finds no capture format. Re-run the capture with `-w capture.pcap`.
  • When would you choose `-i any`, and what do you give up?
    Use it when you do not know which interface carries a flow: a bond, VLAN sub-interfaces, container bridges or policy routing. Each packet is tagged with its interface and direction. You give up the Ethernet header (a cooked pseudo-header keeps only one source link-layer address), promiscuous mode, and you may see a packet twice if it crosses two interfaces. Once you know the interface, capture on it by name.
  • Does reading a capture back with `tcpdump -r` need root?
    No. tcpdump's man page says reading a saved packet file needs no special privileges; only opening a live capture device does. A common practice is to capture with sudo, change the file's owner or copy it, and analyse it as an ordinary user.

saying these in an interview costs you the question

  • Redirecting tcpdump's printed output with > produces a pcap file Wireshark can open.
  • Without -i, tcpdump captures on every interface at once.
  • Capturing on -i any puts every interface into promiscuous mode.
  • The .pcap extension is what makes a file readable as a capture.
  • Reading a saved capture with tcpdump -r needs root, just like capturing.
open as a page

How do you write a tcpdump filter for TCP traffic with 192.0.2.10 on port 5432, and what do its type, dir and proto qualifiers do?

level: juniorimportance: must knowfreq 44%

basics

~20 s

Use tcp port 5432 and host 192.0.2.10. Each primitive is an id with qualifiers: proto (tcp, ip, ip6), dir (src, dst) and type (host, net, port, portrange). Missing ones default to host, src or dst, and every consistent protocol.

open as a page

In a tcpdump TCP line, what do the flag fields [S], [S.], [P.], [F.], [R.] and a bare [.] each tell you?

level: juniorimportance: must knowfreq 40%

basics

~20 s

Each character is one TCP control bit that is set: S SYN, F FIN, P PSH, R RST, U URG, and a dot for ACK. So [S.] is SYN plus ACK, [P.] data with ACK, and [.] a bare acknowledgment.

open as a page

Which tcpdump filter shows only the initial SYN of each TCP handshake, not the SYN-ACK, and why is `tcp[tcpflags] & tcp-syn != 0` not enough?

level: middleimportance: must knowfreq 31%

basics

~20 s

tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn keeps the SYN and ACK bits and requires SYN alone. Testing only the SYN bit also matches every SYN-ACK, because the reply carries SYN too. The numeric form is tcp[13] & 0x12 == 2.

open as a page

A client tcpdump shows one SYN to port 443 sent three times unanswered; how does that look different from a refused connection?

level: middleimportance: must knowfreq 34%

basics

~20 s

Three [S] lines with the same source port and seq are one SYN retransmitted because nothing reached this capture point in reply. A refused attempt is one [S] answered within a round trip by [R.] acking the SYN's seq plus one.

open as a page

How do you run tcpdump for days on a production host to catch an intermittent fault without filling the disk, using -C, -G and -W?

level: middleimportance: should knowfreq 19%

basics

~20 s

Rotate with -C (a new file each time one passes N million bytes) and cap the set with -W for a ring that overwrites the oldest file. -G rotates by time into strftime-named files; with -W it exits after N files.

open as a page

What does tcpdump's -s snapshot length control, what is its default in tcpdump 4.99, and when should you lower it?

level: middleimportance: should knowfreq 24%

basics

~20 s

The snapshot length is how many bytes tcpdump keeps from each packet; tcpdump 4.99 defaults to 262144, effectively whole packets. Lower it to keep headers only when payload must not be stored or the capture must be cheaper.

open as a page

Why does the tcpdump filter `host 192.0.2.10 and port 53 or port 853` show port-853 traffic from other hosts, and how do you fix it?

level: middleimportance: should knowfreq 27%

basics

~20 s

In pcap-filter, and and or have equal precedence and group left to right, so the filter means (host and port 53) or port 853. Write host 192.0.2.10 and (port 53 or 853), single-quoted so the shell keeps the parentheses.

open as a page

Why do operators run tcpdump with `-n` during an incident, and what does tcpdump do without it?

level: middleimportance: should knowfreq 20%

basics

~20 s

Without -n, tcpdump converts addresses to host names with reverse DNS lookups and port numbers to service names. That slows or stalls output, adds DNS traffic, and hides the numbers you need. One -n turns off both.

open as a page

Why does tcpdump print `ack 1` and `seq 1:518` after a handshake, and when do you need `-S` instead?

level: middleimportance: should knowfreq 24%

basics

~20 s

tcpdump subtracts the initial sequence numbers it saw, so the first data byte in each direction is 1 and seq 1:518 covers bytes 1 to 517. -S prints the raw numbers, needed when comparing captures or matching other tools.

open as a page

A tcpdump capture on a busy Linux host ends with '48213 packets dropped by kernel'; what does that count mean, and how do you bring it down?

level: seniorimportance: should knowfreq 16%

basics

~20 s

Dropped by kernel counts packets that matched the filter but were discarded because the OS capture buffer was full; tcpdump fell behind. Reduce it by writing with -w, filtering tighter, lowering snaplen and raising -B.

open as a page

How do you stream a tcpdump capture from a remote Linux server over SSH into Wireshark on your workstation, and why does -U matter?

level: seniorimportance: should knowfreq 13%

basics

~20 s

Run ssh host "sudo tcpdump -i eth0 -U -w - 'not port 22'" | wireshark -k -i -. -w - sends pcap to stdout, -U flushes each packet, and the filter keeps the capture from recording its own SSH stream.

open as a page

On a dual-stack server, why does the tcpdump filter `tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn` show IPv4 SYNs but no IPv6 SYNs, and how do you catch both?

level: seniorimportance: should knowfreq 13%

basics

~20 s

The tcp[...] accessor only matches IPv4: the compiled code first checks for EtherType 0x800. For IPv6, index from the IPv6 header, ip6[6] == 6 and ip6[53] & 0x12 == 0x02, which holds only when no extension header precedes TCP.

open as a page

On a trunk-port capture, why does the tcpdump filter `vlan and host 192.0.2.10 or host 192.0.2.10` miss untagged traffic to that host, and how do you fix it?

level: seniorimportance: should knowfreq 10%

basics

~20 s

The first vlan keyword shifts the decoding offsets by 4 bytes for the rest of the expression, so the second host test reads untagged frames at the wrong place. Put the untagged test first: host 192.0.2.10 or (vlan and host 192.0.2.10).

open as a page

On a Linux server, `tcpdump -v` marks outgoing TCP checksums incorrect and shows 28,960-byte segments on a 1500-byte MTU link; is traffic being corrupted?

level: seniorimportance: should knowfreq 12%

basics

~20 s

Almost certainly not. tcpdump sees outgoing packets before the NIC fills in checksums or splits large buffers, so checksum offload and segmentation offload produce exactly these lines. Receive offload likewise merges inbound segments before the capture.

open as a page

A tcpdump capture of a fast bulk transfer shows `win 502` on every segment; why is that not a 502-byte window?

level: middleimportance: nice to knowfreq 15%

basics

~20 s

tcpdump prints the 16-bit window field exactly as sent and never applies window scaling. The scale comes from the wscale option in each side's SYN; with wscale 7, win 502 means 502 × 128 = 64,256 bytes.

open as a page

Why does tcpdump offer -Z to switch to an unprivileged user after opening the capture device, and what does it change for the files it writes?

level: seniorimportance: nice to knowfreq 6%

basics

~20 s

Opening a live device needs root; parsing hostile packets does not, so -Z user drops root once the device is open. The -w file and rotated files are opened after the switch, so normally that user must be able to write them.

open as a page

What does `tcpdump -d` print for a filter such as `tcp port 25`, and how do you read its loads, jumps and ret lines to confirm what it matches?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

tcpdump -d compiles the filter for the link type and prints one classic BPF instruction per line, then exits. Loads read header bytes, jeq and jset branch to absolute line numbers, ret #262144 accepts up to the snapshot length and ret #0 drops.

open as a page