tcpdump Filter Examples for Everyday Network Troubleshooting
Copy focused tcpdump filters for hosts, networks, DNS and TCP. Learn where to capture, how to save a PCAP and what missing packets really mean.
Read-only command: tcpdump -D
Test one layer at a time. A DNS answer, a TCP connection, a valid TLS certificate and an application response are separate observations. These references help you choose a test that answers the current question and understand what remains untested.
13 references
Read-only results link to an individual observation command. Other commands on the same page can have different effects.
No matching references. Try a task such as packet capture, route lookup, BGP or interface errors.
Use tcpdump and Wireshark to follow packets at a known observation point. Use dig or PowerShell to make a reproducible DNS or port test. Linux ip and ss show the local route, neighbor and socket state. OpenSSL and curl help separate certificate, HTTP and application-facing failures.
Throughput testing needs a different approach from checking connectivity. The iperf3 guide explains test direction, load and result interpretation. Optical-power, VLAN, DHCP and BGP references connect protocol and physical-layer evidence to the next useful check.
The examples are designed to be repeatable with your own addresses and interfaces. Active probes and load tests are identified separately from reading local state. When a calculation is needed, use the related subnet, MTU, bandwidth or optical-budget tool rather than estimating from memory.
Copy focused tcpdump filters for hosts, networks, DNS and TCP. Learn where to capture, how to save a PCAP and what missing packets really mean.
Read-only command: tcpdump -D
Find practical Wireshark display filters and matching capture filters for hosts, ports, DNS and TCP. Avoid common mistakes when investigating packet loss.
Read-only command: ip.addr == 192.0.2.20 && tcp.port == 443
Diagnose DNS with dig: choose a resolver, compare A and AAAA answers, test TCP, inspect response codes and distinguish NXDOMAIN from an empty answer.
Use Test-NetConnection, Resolve-DnsName and Get-NetTCPConnection to separate DNS, route, TCP and local-listener problems on Windows.
Read-only command: Get-NetTCPConnection -State Listen -LocalPort 443
Inspect Linux addresses, route selection, neighbors and sockets with read-only ip and ss commands. Find the right interface and local listener before changing configuration.
Read-only command: ip -br address show
Check a server certificate with OpenSSL while preserving SNI and hostname verification. Inspect expiry, SAN names and the difference between a supplied and trusted chain.
Read-only command: openssl x509 -in server.pem -noout -subject -issuer -dates
Separate DNS, TCP, TLS and HTTP failures with curl. Test one backend with --resolve, preserve hostname verification and read timing results correctly.
Run repeatable iperf3 tests and interpret single-stream, reverse and UDP results. Separate path capacity from endpoint limits without hiding weak performance.
Interpret all six BGP neighbor states, common reset reasons and an Established session with zero routes. Start with targeted read-only checks.
Read-only command: show ip bgp summary
Interpret SFP receive power, alarms and growing CRC counters. Compare both ends, use the actual optic limits and avoid replacing parts without evidence.
Read-only command: show interfaces diagnostics optics xe-0/0/0
Understand tagged and untagged VLAN traffic across vendors. Compare ingress classification, allowed membership and egress tagging before changing a port.
Read-only command: /interface bridge port print detail
Locate a DHCPv4 failure by following Discover, Offer, Request and ACK. Use packet evidence to distinguish VLAN, relay, scope and client problems.
Read-only command: udp port 67 or udp port 68
Find interface, IPv4 route and BGP inspection commands across FortiGate, MikroTik, Junos and Cisco, with context and links to detailed references.
Read-only command: get system interface physical