Packet Filtering: Catching the Cool Packets


There are two filters that are my absolute favorites - the ICMP filter and the broadcast filter. The broadcast filter can be made using the address filter techniques covered in the previous chapter. The ICMP filter, however, can be made with a simple protocol selection in most analyzer products.

Why do I care sooooo much about the ICMP filter. Well, first of all, get the "TCP/IP Analysis and Troubleshooting" book and start reading around page 60. Wow! When I go onsite, I usually capture all the packets (no filters applied) and then look specifically for the ICMP traffic crossing the wire. Here are some examples of what I can learn using an ICMP filter:

ICMP is one of my favorite protocols in the TCP/IP protocol suite. I highly recommend you spend some time with RFC 792 and RFC 1256.


Категории