How can I filter for traffic only a specific port?

I am watching the traffic on a machine coming and going to a server, and we frequently have a dropped connection. I would like to see the traffic on the port that the 2 machines communicate on to see if we can determine what precipitates the drops.

Are you asking about a protocol port (TCP/UDP) or a network interface port (NIC)?

Chuckc ( 2020-12-04 13:57:58 +0000 )

As noted in the user guide, there are two types of filters; capture filters that limit the traffic that is captured and display filters that limit the traffic that is displayed from a capture.

While a capture filter can be useful to limit the traffic under investigation, when troubleshooting certain issues the capture filter can drop packets that may be essential, e.g. icmp, so at first don't set a capture filter. The capture filter syntax is detailed here, some examples can be found here and in general a port filter is port <port number>.

Display filter syntax is detailed here and some examples can be found here and a port filter for tcp is tcp.port == <port number> and for udp is udp.port == <port number>.

