How does tcpdump capture packets?
Issue
- How does tcpdump capture packets?
- Where does libpcap get the packets?
- How do offloading features affect pcap trace?
- Which side of the iptables firewall are packets captured?
Environment
- Red Hat Enterprise Linux
- tcpdump, Wireshark, tshark, or other libpcap-based network packet capture method
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.