How-to – Capturing with tcpdump for viewing with Wireshark


It’s often more useful to capture packets using tcpdump and show them result on Wireshark.

$ tcpdump -i <interface> -s 65535 -w <some-file>

You will have to specify the correct interface and the name of a file to save into.
In addition, you will have to terminate the capture with ^C when you believe you have captured enough packets.