---
tags:
- networking
- l1
- flashcard-deck
- networking-troubleshooting-tools
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Networking Troubleshooting Tools](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
tcpdump/a1b2c3d4e5f6	tcpdump	easy	tcpdump,options,interface	What does tcpdump -i eth0 do?	Captures packets on the eth0 interface only. Use -i any to capture on all interfaces.\n\nRemember: "tcpdump -i = interface, -n = numeric, -w = write, -r = read." The essential four flags.\n\nExample: tcpdump -ni eth0 -w capture.pcap -c 100 captures 100 packets on eth0 to a file.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/b2c3d4e5f6a7	tcpdump	easy	tcpdump,options,name-resolution	What does the -nn flag do in tcpdump?	Disables both hostname and port name resolution so output shows raw IP addresses and port numbers. Faster and clearer for debugging.\n\nRemember: "Two n's = no names at all." -n disables host resolution, -nn disables both host and port name resolution.\n\nGotcha: Without -nn, tcpdump does reverse DNS lookups for every packet — very slow on busy networks.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/c3d4e5f6a7b8	tcpdump	easy	tcpdump,options,write	How do you save a tcpdump capture for later analysis?	Use -w file.pcap to write packets to a pcap file. Read it back with tcpdump -r file.pcap or open it in Wireshark.\n\nRemember: "pcap = packet capture format." Wireshark, tcpdump, and tshark all use pcap. -w writes it, -r reads it.\n\nExample: Capture on server, analyze on laptop: tcpdump -w cap.pcap on server, then scp + wireshark on laptop.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/d4e5f6a7b8c9	tcpdump	easy	tcpdump,filter,port	How do you capture only DNS traffic with tcpdump?	tcpdump -ni any port 53. DNS uses port 53 for both UDP queries and TCP fallback.\n\nRemember: "Port 53 = DNS." UDP for queries, TCP for zone transfers and large responses.\n\nFun fact: DNS was one of the first internet protocols (RFC 1035, 1987).	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/e5f6a7b8c9d0	tcpdump	medium	tcpdump,filter,compound	How do you filter tcpdump for traffic to a specific host AND port?	Use a compound filter: tcpdump -ni eth0 'host 1.2.3.4 and port 80'. Filters support and, or, not, and parentheses for grouping.\n\nRemember: "tcpdump filter syntax = BPF (Berkeley Packet Filter)." Operators: and, or, not. Wrap complex filters in quotes.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/f6a7b8c9d0e1	tcpdump	medium	tcpdump,filter,direction	How do you capture only traffic originating from a specific IP?	Use src: tcpdump -ni eth0 src host 10.0.0.5. Similarly, dst host filters on destination only.\n\nRemember: "src = source, dst = destination." Both can filter by host or port.\n\nExample: tcpdump -ni eth0 'src port 80' captures only responses FROM port 80 (web server replies).	zines/bite.size.networking.cleaned.notes
tcpdump/a7b8c9d0e1f2	tcpdump	medium	tcpdump,output,handshake	What TCP flags should you look for in tcpdump output to confirm a successful connection?	SYN (client initiates), SYN-ACK (server responds), ACK (client confirms). This three-way handshake completes the TCP connection. Missing SYN-ACK often means firewall or service not listening.\n\nRemember: "SYN-SYN/ACK-ACK = TCP three-way handshake." Flags in tcpdump: [S] = SYN, [S.] = SYN-ACK, [.] = ACK.\n\nGotcha: [R] = RST (connection reset) — often means port closed or firewall rejection.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/b8c9d0e1f2a3	tcpdump	medium	tcpdump,options,snaplen	What does -s 0 do in tcpdump and when should you use it?	Sets snapshot length to capture the full packet (no truncation). Use it when you need complete payload data, such as when saving pcaps for detailed analysis. Default snaplen may truncate large packets.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/c9d0e1f2a3b4	tcpdump	medium	tcpdump,options,ascii	What is the difference between tcpdump -A and tcpdump -X?	-A prints packet payload in ASCII only. -X prints payload in both hex and ASCII. Use -A for readable text protocols like HTTP; use -X for binary protocol inspection.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/d0e1f2a3b4c5	tcpdump	hard	tcpdump,gotchas,interface	You run tcpdump and see zero packets. What are the most likely causes?	Wrong interface (-i eth0 vs -i any), wrong network namespace (containers have separate namespaces), filter too restrictive, traffic offloaded by NIC hardware, or insufficient privileges (need root/CAP_NET_RAW).	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/e1f2a3b4c5d6	tcpdump	hard	tcpdump,workflow,dns-debug	Describe a tcpdump workflow to debug DNS resolution failure.	1. Run: tcpdump -ni any port 53\n2. Trigger the DNS lookup (dig or application request)\n3. Check: are queries leaving? Which resolver IP?\n4. Check: are responses returning? What response code?\n5. Look for retransmissions (resolver unreachable) or NXDOMAIN/SERVFAIL responses.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/f2a3b4c5d6e7	tcpdump	easy	tcpdump,options,count	How do you limit tcpdump to capture only N packets?	Use -c N. For example, tcpdump -c 10 -ni any port 80 captures exactly 10 packets matching the filter, then exits.\n\nRemember: "Retransmissions = packet loss." If you see the same sequence number repeated, packets aren't getting through.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/a3b4c5d6e7f8	tcpdump	medium	tcpdump,output,retransmit	What does seeing retransmissions in tcpdump output indicate?	Packets are being sent but not acknowledged. Common causes: network congestion, packet loss, firewall dropping packets silently, or the remote host is too slow to respond. Look at timing gaps between retransmits.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/b4c5d6e7f8a9	tcpdump	hard	tcpdump,tls,https	Can tcpdump decrypt HTTPS traffic? What can you still learn from it?	No, tcpdump cannot decrypt TLS-encrypted payloads. But you can still observe: connection timing, TLS handshake initiation (ClientHello), retransmits, resets, certificate exchange size/timing, and whether the connection completes at all.	zines/lets.learn.tcpdump.zine.cleaned.notes
tcpdump/c5d6e7f8a9b0	tcpdump	medium	tcpdump,filter,protocol	How do you capture only TCP or only UDP traffic?	Use the protocol keyword as the filter: tcpdump -ni any tcp or tcpdump -ni any udp. Can be combined: tcpdump -ni any 'tcp port 443 or udp port 53'.	zines/bite.size.networking.cleaned.notes

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Networking Troubleshooting](../../../../library/topics/networking-troubleshooting/index.md) (Topic Pack, L1) — Networking Troubleshooting Tools

<!-- wiki:related:end -->
