2
I want to create a filter which has 2 conditions:-
- Filter packets with network.
(src net 2a01:111:xxxx::/44)
- Filter based on tcp handshake alert messages.
(tcp[((tcp[12] & 0xf0) >> 2)] = 0x15)
Both filters work individually but when combined together with:-
sudo tcpdump -s 1024 -v -ni any "(src net 2a01:111:xxxx::/44) and (tcp[((tcp[12] & 0xf0) >> 2)] = 0x15)"
,
it fails with error:
tcpdump: expression rejects all packets
.
I'm not sure how logical AND of these 2 filters results in no packets to get filtered.
Wow, that's unexpected and as always, man-page has the answer. Thanks @Spiff for the answer. – Abhijeet Rastogi – 2019-10-14T19:20:42.340