Forum Discussion
tcpdump excluding monitor traffic
This has always been a pain. To help with this, I have try where possible to use a SNAT pool rather than automap. However, it's obviously too late for that now. You could do it with two passes through tcpdump. The first pass you capture traffic to the virtual IP and include the 😛 flag. You then filter the output of that to exclude the VS IP:
tcpdump -i external:nnnp -s0 -w - host 10.1.2.3 | tcpdump -r - -s0 not host 10.1.2.3
Or, probably more usefully, save the capture from the first command, and process it afterwards:
tcpdump -i external:nnnp -s0 -w /var/tmp/my.cap host 10.1.2.3
tcpdump -r /var/tmp/my.cap -s0 not host 10.1.2.3
That's off the top of my head, I haven't tested it. If it's not quite right, hopefully you get the idea.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
