//抓取一个子网范围 tcpdump -i bond0 port 3001 and net 1.2.3.0/24 and host not 1.2.3.211 -nn -X
//抓取 DNAT 包,tcp options 里面的 246 代表 DNAT tcpdump -nn –vvv -i eth0 tcp dst port 3306 and '(tcp[tcpflags] & (tcp-syn) != 0) and (tcp[20] =246) '
//在上面的基础上,抓取指定 vip:10.142.*.* tcpdump -nn –vvv -i eth0 tcp dst port 3306 and '(tcp[tcpflags] & (tcp-syn) != 0) and tcp[20]=246 and tcp[24]=10 and tcp[25]=142'
//抓取 DNAT 包,tcp options 里面的 252 代表 DNAT tcpdump -nn –vvv -i eth0 tcp dst port 3306 and '(tcp[tcpflags] & (tcp-ack) != 0) and (tcp[20] =252) '
//根据指定的VPC IP抓包,例如172.16.x.x tcpdump -nn –vvv -i eth0 tcp dst port 3306 and '(tcp[tcpflags] & (tcp-ack) != 0) and (tcp[32] =172) and (tcp[33] =16)'
//根据客户端IP抓包FNAT的包,例如172.16.x.x tcpdump -nn –vvv -i eth0 tcp dst port 3306 and '(tcp[tcpflags] & (tcp-ack) != 0) and(tcp[20]=252) and (tcp[24]=172) and (tcp[25]=16)'
用tcpdump抓取并保存包: sudo tcpdump -i eth0 port 3306 -w plantegg.cap