Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Filtering rules commonly used in wireshark

Shulou Source: shulou.com Published: 2022-06-01 02:24:10 10月04日 Update

1. Find the destination address and source address "

Ip.src = = 10.1086.90 and ip.dst eq 115.29.47.145

two。 Filter port

If tcp.port = = 80, the packets with source port and destination port 80 are filtered out.

If tcp.srcport = 80, only packets with source port 80 are filtered.

3. Protocol filtering

Enter the protocol name directly in the filter box. For example, if you filter the HTTP protocol, http

4.http mode filtering

Filter get packets: http.request.method = = "GET"

Filter post packets: http.request.method = = "POST"

5. Connector and

Use and connections when filtering multiple conditions

Ip.src = = 10.10.86.90 and http

Tags: Port address destination multiple condition mode input common rule Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux Xiaomi Shulou Information vpn Shulou Technology