Ask Your Question
0

How can I use dumpcap to capture traffic only on port 53?

asked 2018-10-12 19:26:21 +0000

updated 2018-10-13 14:34:01 +0000

grahamb gravatar image

I have a server set up that runs a continuous capture for one of my branches. My current argument is:

"C:\Program Files\Wireshark\dumpcap.exe" -i 2 -b files:80 -b filesize:512000 -port 53 -w e:\Captures\COL3_VoIP_Capture.pcap

This works great for capturing ALL traffic. However, I want to set it up to only capture DNS queries. I have tried the following, but it doesn't seem to work.

"C:\Program Files\Wireshark\dumpcap.exe" -i 2 -f "port 53" -b files:80 -b filesize:512000 -port 53 -w e:\Captures\COL3_VoIP_Capture.pcap

Any help would be appreciated!

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2018-10-12 20:15:56 +0000

cmaynard gravatar image

First, -port 53 is an invalid option so you should remove that.

Otherwise the -f "port 53" option should capture all DNS traffic. Are you capturing on the right interface? If you're not sure which interface to capture on, you could try capturing on multiple interfaces at once using a series of -i <n> options for as many interfaces as you have.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2018-10-12 19:26:21 +0000

Seen: 673 times

Last updated: Oct 13 '18