
20 Nov
2012
20 Nov
'12
1:20 a.m.
On 20/11/12 09:35, Trent W. Buck wrote:
IME best practice is to put tcpdump on your router, run tcpdump -wfoo.pcap
You want to add -s0 to that if you want to capture the whole packet (tshark does that automatically). cheers, Chris -- Chris Samuel : http://www.csamuel.org/ : Melbourne, VIC