Topic 6.4
Packet Capture: tcpdump & Wireshark
In one line
When logs and guesses disagree, packets tell the truth. tcpdump captures traffic on an interface with a filter (host, port, protocol), shows it live or saves it to a .pcap file, and Wireshark opens that file to decode every layer and follow whole conversations. Capture on the right host and interface, filter tightly, keep captures short, and treat them as sensitive data.
Think of it like this
A CCTV camera at a shop's door. Instead of asking staff 'did the delivery arrive?', you rewind the recording and see exactly who came, when, and what they carried.
Words you'll meet
New words in this topic, in plain English. Come back here whenever one feels fuzzy.
- Packet capture
- Recording network packets as they pass an interface, for later analysis.
- tcpdump
- A command-line packet capture tool available on almost every Linux system.
- Wireshark
- A graphical tool that decodes captured packets layer by layer.
- pcap
- The standard file format for saved packet captures.
- BPF filter
- The capture filter language tcpdump uses (
host,port,tcp,and,not). - Retransmission
- TCP re-sending a packet that wasn't acknowledged in time, a sign of loss.
Step by step
01Is the request even arriving?
Some Tiffin orders fail with 'payment gateway timeout'. The app team says it sent the request, and the payment provider says it never arrived. Arjun captures on the API server, filtered to the provider's port, while retrying one payment.
02Narrowing it down
The provider's capture shows no SYN from Tiffin's NAT gateway IP. The NAT gateway's metrics show 'port allocation errors': it ran out of source ports for that one destination (Topic 4.3). The packets were dropped at the NAT, which no application log could show.
03Saving and analysing in Wireshark
For a slow-response investigation, Priya saves a two-minute capture, copies it to her laptop, and opens it in Wireshark. The 'tcp.analysis.retransmission' filter instantly shows packet loss on one path, and 'Follow TCP Stream' shows the request and response together.
04Capturing inside containers and pods
A container has its own network namespace, so capturing on the host's eth0 may miss traffic between containers. Run tcpdump inside the namespace: kubectl debug with a netshoot image attaches to a pod's network.
Break it on purpose
Errors are the best teachers. Make each change, read the error, guess what went wrong, then reveal the answer.
Break #1
Capturing on the wrong interface
Arjun runs tcpdump -n port 5432 on a server with several interfaces to debug a database connection.
Myth vs fact
Myth
HTTPS makes packet captures useless.
Fact
You can't read the encrypted payload, but you still see who connected, when, handshake success or failure, resets, retransmissions, and timings, which solves most network problems.
Pro corner
Extra depth for experienced readers. New to this? Skip it for now and come back later.
- ▸
To decrypt your own TLS traffic in a test environment, set
SSLKEYLOGFILE=/tmp/keys.logfor curl, browsers, or Node, and point Wireshark at the key log (Preferences → Protocols → TLS). Never do this with production user traffic.
Remember this
- 1
tcpdump -ni <iface> '<filter>':-nskips DNS lookups (faster, no extra traffic),-i anycaptures all interfaces, and filters look likehost 10.0.1.20 and port 5432. - 2
Read TCP flags:
[S]SYN,[S.]SYN-ACK,[.]ACK,[P.]data,[F.]FIN,[R]reset. A SYN with no reply means a drop on the way. A SYN answered by[R]means refused. - 3
Save with
-w file.pcap(add-s 0for full packets on old versions, and-c 1000to stop after 1,000 packets), then open it in Wireshark on your laptop. - 4
Wireshark's display filters (
tcp.port == 443,dns,http.response.code >= 500,tcp.analysis.retransmission) and 'Follow TCP Stream' turn thousands of packets into one readable conversation. - 5
Capture at both ends when unsure: if the client sends a SYN and the server never sees it, the drop is between them.
- 6
Captures contain real data (cookies, tokens, personal information in plaintext protocols). Capture only what you need, store them securely, and delete them after the investigation.
Explain it without notes
What does a capture showing repeated SYNs and no SYN-ACK tell you?
Why capture at both ends of a connection?
Practice
Capture a DNS lookup and identify the query and answer.
Save a capture of an HTTP request and open it in Wireshark.
Trade-offs
- ↔
Captures give ground truth but are heavy (disk, CPU at high rates) and sensitive. Tight filters and short durations keep both manageable. Flow logs (VPC Flow Logs) are lighter but only show connection summaries, not packets.
Done when you can
I can capture with a tight filter on the right interface.
I can read SYN, RST, and retransmissions.
I treat captures as sensitive data.