RHEL6 Requirements:
geoip-1.4.6-1.el6.rf.x86_64.rpm
libsmi-0.4.8-4.el6.x86_64.rpm
wireshark-1.10.0-1.el6.rft.x86_64.rpm
wireshark-gnome-1.10.0-1.el6.rft.x86_64.rpm
zlib-1.2.3-29.el6.x86_64.rpm
For remote capture readings:
coreutils-8.4-43.el6.x86_64.rpm
coreutils-libs-8.4-43.el6.x86_64.rpm
Create a named pipe:
mkfifo /tmp/packet_capture
Start wireshark from the command line
wireshark -k -i /tmp/packet_capture
Run tcpdump over ssh on your remote machine and redirect the packets to the named pipe (find the eth interface):
ssh root@source-hostname "tcpdump -s 0 -U -n -w - -i eth0 not port 22" > /tmp/packet_capture
Source: http://blog.nielshorn.net/2010/02/using-wireshark-with-remote-capturing/
Filters
===
Find duplicate ip addresses:
arp.duplicate-address-detected
Exclude a destination ip address
NOT(ip.dst == 10.15.30.114)
Exclude a source ip address
NOT(ip.src == 10.15.30.114)
Comments