Common rules of Wireshark
Common filtering rules:
Filter IP address: ip.addr = = 192.168.47.2 filter destination address: ip.dst = = 192.168.43.2 filter source address: ip.src = = 59.110.42.77 filter tcp 80 port and udp 80 port data (| | indicate or): tcp.port = = 80 | udp.port = = 80 filter data with destination port 80: itcp.dstport==80 filter data with source port 80: tcp.srcport==80 filtering protocol (direct input) Input protocol name): http http mode filtering: filtering get packets Http.request.method== "GET" filter post packets, http.request.method== "POST" filter two conditions, use and connection: filter ip is 192.168.101.8 and is http protocol, ip.src==192.168.101.8 and http filter port range: tcp.port > = 1 and tcp.port TCP Streamfollow-> UDP Stream
Appendix:
For example, post a form, if the form is very large, it will fragment the tcp stream. A piece of data like "TCP segment of a reassembled PDU" is displayed in wireshark.