help with tcpdump cmd syntax

fbsd_user fbsd_user at
Sat Apr 8 12:56:35 UTC 2006

I tried 
   tcpdump -i rl0 src host -w /usr/
   tcpdump -i rl0 host -w /usr/
   tcpdump -i rl0 src ip -w /usr/  

but got syntax error msg with no hint of what was wrong

If I remove the -w stuff it works. Meaning it prints to the screen.
But I want to write to file

Can you help me out here on the syntax error?

One other thing. When does tcpdump get access to the packet?

My firewall has a block log rule for that ip address. 
Does tcpdump see the packet before ipfilter ipnat does?


More information about the freebsd-questions mailing list