Hello. I am a new user to Ethereal and currently have 0.8.12 installed on a Linux Redhat 6.2 laptop. I have been successful in capturing packets and am quite impressed at the level of decode. I am attempting to analyze a BGP problem between two dissimilar routers. When I open the capture filter window, I am able to enter the key word tcp to see only that traffic on the wire. However, I would prefer to see only bgp messages or tcp.port == 179 packets. When I try either of those syntax forms in the filter window, I get a "can't parse" message with an unreadable error code. TIA for any help or guidance. BTW, I am aware that there are two capture syntax forms but I thought the suntax listed in the man page for ethereal is the correct one for the capture window. I have not tried the tcpdump syntax. Chuck -- Chuck Phillips Cyberguard Corporation (954) 958-3900 ext 3420 (954) 958-3899 fax (954) 224-6528 cell 8774741434@xxxxxxxxxx cphillips@xxxxxxxxxxxxxx chucklp@xxxxxxxxxxxxx
Powered by MHonArc 2.6.10