> TIA for any help or guidance. BTW, I am aware that there are > two capture syntax forms Umm, actually, you can't possibly be aware of that, as there currently *aren't* two capture syntax forms. > but I thought the suntax listed in > the man page for ethereal is the correct one for the capture > window. The syntax listed in the Ethereal man page is the correct one for *display* filters; display filters are used for, well, filtering the display, as well as for searching for packets, but they're not used for filtering captures. > I have not tried the tcpdump syntax. Try that - it's the *only* syntax for capture filters. BGP is TCP port 179, so the tcpdump-syntax capture filter is tcp port 179
Powered by MHonArc 2.6.10