Chapter13. Tools
Protocol/Port Selection
Youcan limit the selection by specifying certain protocols.

All IP protocols

Norestriction regarding protocols.

TCP/UDP

Whenselecting TCP or UDP, you can choose all packets or packets to certain ports only.
Inthese fields, you can enter a single port number (32), a range of port numbers (1-1023), alist of port numbers and
rangesseparated by commas (53, 1024-65535) or nothing at all. If the field is empty, any port will match. See
appendixG, Lists of ports, ICMP and protocols, for more information on port numbers.
Ifyou want to study all traffic except the one to or from a specific port or group of ports, enter the port number(s)
hereand mark the "not this port" box.
Theselection can be modified by the control boxes under the fields A and B:
Asrc Packetsfrom the port number in field A matches. Field B is ignored.
Adst Packetsto the port number in field A matches. Field B is ignored.
Aany Packetsto or from the port number in field A matches. Field B is ignored.
Ato B Packetsfrom A to B matches.
Bto A Packetsfrom B to A matches.
BetweenA&B Packetsfrom A to B, or from B to A, matches.
notthis combination Packetsthat do not match the given combination of A and B are shown in
thelog.
Ifyou, for example, want to search for all packets to a web server, but not packets on the "normal" client and server
portsin your environment, fill in the form like this:

ICMP

ICMPpackets contain a type field and a code field. When searching for ICMP packets, you can select all packets or
119