Misadventures with tcpdump Filters
For quite some time I’ve been running into a tricksome situation with tcpdump. I discovered the problem is entirely to do with 802.1q tagged packets. Since this pcap was taken from a mirrored port of a switch using VLANs it follows all the same rules as a trunked interface.
Mon 03 Sep 2012 11:44:29 AM AEST - permalink -
-
http://security.blogoverflow.com/2012/08/misadventures-with-tcpdump-filters/