in reply to Re^2: filter tcpdump packets
in thread filter tcpdump packets
Tshark is another application that identical to Tcpdump
No, it's much more powerful - have a look again at the tshark manpage, especially the -T fields and -e options. You can use them to output Wireshark's tcp.options.mss_val field.
As for your output, it looks like the packets don't contain an MSS option, or, if you know the packets do have one, NetPacket::TCP isn't parsing them correctly, in that case file a bug with the module.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: filter tcpdump packets
by syboar (Novice) on Sep 01, 2014 at 12:38 UTC |