Wireshark mailing list archives

limit of IP filters in dumpcap


From: Jianhong Xia <jianhong.xia () zingbox com>
Date: Tue, 18 Apr 2017 02:08:40 +0000

Hi,

I am not sure if anyone asked this question before.

I am using dumpcap to capture network traffic with thousands of clients from local sub-network. I would like to use IP 
filter to capture the traffic from/to selectively IP addresses. I know if I have a few IP addresses to capture, I can 
use

dumpcap -i en0 -f 'host x.a.b.c and host x.d.e.f and host x.g.h.i'  -w traffic.pcap


However, if I have thousands of IP addresses that I want to capture their traffic, how many IP address filters that 
dumpcap can support?

Thanks,
Jianhong

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: