↓ Skip to main content

tcpdump cheatsheet: capture and troubleshoot network traffic

·1097 words·6 mins·
Photo by Mohammad O Siddiqui on Unsplash
tcpdump is a quick way to see what is happening on a network interface. This cheatsheet collects the commands and Berkeley Packet Filter (BPF) expressions used for everyday troubleshooting: choosing an interface, narrowing a capture, reading packets, saving evidence, and investigating TCP and DNS problems.

Before you start
#

Most captures require root privileges. Use sudo when tcpdump cannot open the interface or capture device.

sudo tcpdump -D                         # List capture interfaces
sudo tcpdump -i eth0                    # Capture on eth0
sudo tcpdump -i any                     # Capture on all interfaces (Linux)
sudo tcpdump -i eth0 -c 20              # Stop after a fixed number of packets

A capture runs until you press Ctrl+C unless -c limits it.

Useful output options
#

sudo tcpdump -i eth0 -nn               # Do not resolve hostnames or service names
sudo tcpdump -i eth0 -N                # Do not print the domain part of hostnames
sudo tcpdump -i eth0 -v                # Verbose packet details
sudo tcpdump -i eth0 -vv               # More verbose packet details
sudo tcpdump -i eth0 -tttt             # Human-readable timestamps with date and time
sudo tcpdump -i eth0 -q                # Print less protocol information
sudo tcpdump -i eth0 -X                # Print packet data in hex and ASCII
sudo tcpdump -i eth0 -A                # Print packet data as ASCII
sudo tcpdump -i eth0 -e                # Include the link-layer header and MAC addresses

Start with -nn -tttt when troubleshooting. Name lookups can slow a capture and hide the timing of a problem.

Capture size and duration
#

sudo tcpdump -i eth0 -s 0                       # Capture the complete packet
sudo tcpdump -i eth0 -c 100                     # Capture 100 packets
sudo tcpdump -i eth0 -s 0 -c 100 -w capture.pcap # Save 100 complete packets
sudo tcpdump -i eth0 -G 300 -w 'capture-%Y%m%d-%H%M%S.pcap' # Rotate every 5 minutes

The default snapshot length may truncate payloads. Use -s 0 when the payload matters. Full-packet captures use more disk space and may contain sensitive data.

Basic filters
#

Filters are written after the command options. Quote a filter when it contains shell operators or parentheses.

sudo tcpdump -i eth0 host 192.0.2.10             # Traffic to or from one host
sudo tcpdump -i eth0 src host 192.0.2.10         # Traffic from a host
sudo tcpdump -i eth0 dst host 192.0.2.10         # Traffic to a host
sudo tcpdump -i eth0 port 443                    # Traffic on one port
sudo tcpdump -i eth0 src port 53                 # Traffic from source port 53
sudo tcpdump -i eth0 net 192.0.2.0/24            # Traffic for a network
sudo tcpdump -i eth0 'host 192.0.2.10 and port 443'
sudo tcpdump -i eth0 'src host 192.0.2.10 and dst port 22'
sudo tcpdump -i eth0 'port 80 or port 443'
sudo tcpdump -i eth0 'not port 22'

Use parentheses to make precedence explicit:

sudo tcpdump -i eth0 '(host 192.0.2.10 or host 192.0.2.11) and port 443'
sudo tcpdump -i eth0 'tcp and not (port 22 or port 443)'

Protocol filters
#

sudo tcpdump -i eth0 tcp                    # TCP packets
sudo tcpdump -i eth0 udp                    # UDP packets
sudo tcpdump -i eth0 icmp                   # ICMP packets
sudo tcpdump -i eth0 ip                     # IPv4 packets
sudo tcpdump -i eth0 ip6                    # IPv6 packets
sudo tcpdump -i eth0 arp                    # ARP traffic
sudo tcpdump -i eth0 'tcp port 443'         # HTTPS transport
sudo tcpdump -i eth0 'udp port 53'          # Typical DNS over UDP

TCP flags and connection state
#

sudo tcpdump -i eth0 'tcp[tcpflags] & tcp-syn != 0'                         # SYN packets
sudo tcpdump -i eth0 'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn'         # Initial SYN only
sudo tcpdump -i eth0 'tcp[tcpflags] & tcp-rst != 0'                         # Resets
sudo tcpdump -i eth0 'tcp[tcpflags] & tcp-fin != 0'                         # Connection closes
sudo tcpdump -i eth0 'tcp[tcpflags] & (tcp-syn|tcp-fin|tcp-rst) != 0'       # Key state changes

The initial TCP handshake normally looks like S, S., then .. A repeated S with no reply can point to a reachability, routing, firewall, or service-listening problem. An R means that a host or intermediary actively reset the connection.

Read and replay a capture
#

sudo tcpdump -i eth0 -nn -s 0 -w capture.pcap 'host 192.0.2.10'
tcpdump -nn -tttt -r capture.pcap                 # Read a saved capture
tcpdump -nn -r capture.pcap 'tcp port 443'        # Filter while reading
tcpdump -nn -tttt -vv -r capture.pcap             # Read with verbose details
tcpdump -nn -X -r capture.pcap                    # Inspect payload bytes

Use the narrowest useful filter when you can. If you are unsure what matters, save a short broad capture first and apply filters while reading it.

Common troubleshooting recipes
#

Is the host reachable?
#

sudo tcpdump -i any -nn 'host 192.0.2.10'

Look for packets leaving the expected interface and replies coming back. If the request leaves but no reply arrives, inspect routing, firewall rules, security groups, and the destination host.

Is a service listening?
#

sudo tcpdump -i any -nn 'tcp port 8443'

Connect to the service from another terminal. A SYN followed by R. usually means the host rejected the connection. A SYN with no response may mean that the packet was filtered or the return path is broken.

Investigate DNS
#

sudo tcpdump -i any -nn -vv 'port 53'
sudo tcpdump -i any -nn -X 'udp port 53'

The first command shows request and response timing. The second can expose the queried name and response contents when the traffic is unencrypted.

Inspect SSH connections
#

sudo tcpdump -i any -nn -tttt 'tcp port 22'
sudo tcpdump -i any -nn 'host 192.0.2.10 and tcp port 22'

After the SSH handshake, the payload is encrypted. Packet timing, direction, retransmissions, resets, and connection duration remain visible.

Find retransmissions and unusual TCP behavior
#

sudo tcpdump -i eth0 -nn 'tcp[tcpflags] & tcp-ack != 0'
sudo tcpdump -i eth0 -nn 'tcp[tcpflags] & tcp-rst != 0'

Compare sequence and acknowledgment numbers in a verbose capture. Repeated packets with the same sequence number often indicate loss and retransmission. Resets indicate an active close or rejection.

Handy tips
#

  • Start with -nn to remove DNS and service-name lookup noise.
  • Use -i any for a quick first look, then switch to the exact interface when direction or duplicate packets matter.
  • Add -s 0 before inspecting payloads; otherwise, useful bytes may be truncated.
  • Save short captures with -w so they can be reviewed without repeating the incident.
  • Quote filters containing and, or, not, or parentheses so the shell does not interpret them.
  • Capture only what you need. PCAP files may contain credentials, cookies, personal data, or other confidential traffic.
  • For large or long-running captures, rotate files with -G and monitor disk usage.

References
#