Wireshark
常用过滤规则
ip.addr == 192.168.1.1
http && ip.addr == 10.0.0.1
tcp.port == 8080
tcp.flags
udp
ftp
ntp
dns
bootp
igmp
arp
ppp || pppoe
icmp || icmpv6找不到接口问题处理
sc query npf # check npf status
net start npf # start npf
sc query npf # check npf statusreassemble IP packet
设置接口的捕获过滤器

Last updated