Originally Posted by EdH View Post
Thanks! I'll check these out.
You're most welcome. IMO, tcpdump is a required tool in a networking geeks toolbox.

When I'm in a new network, I will often run a "tcpdump -nli any -s 65535 -w datestring.tcp" command to "sniff-the-wire", and see what the other participants on the network might be doing...

Another thing... If there's a particular host pairing, protocol type, etc you're interested in something you can do is add an IPTables rule, and then do an "iptables -nvL | less" to view the counters (both packet counts and bytes).
