System information
Manual:Tools/Packet Sniffer
83
Manual:Tools/Packet Sniffer
Applies to RouterOS: v5.8+
Summary
Sub-menu: /tool sniffer
Packages required: system
Packet sniffer is a tool that can capture and analyze packets that are going to, leaving or going through the router
(except the traffic that passes only through the switch chip).
Packet Sniffer Configuration
Sub-menu: /tool sniffer
Propertyfile-limit (integer 10..4294967295[KiB]; Default: 1000KiB)file-name (string; Default:
)filter-ip-address (ip/mask[,ip/mask] (max 16 items); Default: )filter-mac-address
(mac/mask[,mac/mask] (max 16 items); Default: )filter-port ([!]port[,port] (max 16 items); Default:
)filter-ip-protocol ([!]protocol[,protocol] (max 16 items); Default: )filter-mac-protocol
([!]protocol[,protocol] (max 16 items); Default: )filter-stream (yes | no; Default:
yes)filter-direction (any | rx | tx; Default: )interface (all | name; Default: all)memory-limit
(integer 10..4294967295[KiB]; Default: 100KiB)memory-scroll (yes | no; Default: yes)only-headers (yes
| no; Default: no)streaming-enabled (yes | no; Default: no)streaming-server (IP; Default:
0.0.0.0)DescriptionFile size limit. Sniffer will stop when limit is reached.Name of the file where sniffed packets will
be saved.Up to 16 ip addresses used as a filterUp to 16 MAC addresses and MAC address masks used as a filterUp
to 16 comma separated entries used as a filterUp to 16 comma separated entries used as a filter IP protocols (instead
of protocol names, protocol number can be used)
• ipsec-ah - IPsec AH protocol
• ipsec-esp - IPsec ESP protocol
• ddp - datagram delivery protocol
• egp - exterior gateway protocol
• ggp - gateway-gateway protocol
• gre - general routing encapsulation
• hmp - host monitoring protocol
• idpr-cmtp - idpr control message transport
• icmp - internet control message protocol
• icmpv6 - internet control message protocol v6
• igmp - internet group management protocol
• ipencap - ip encapsulated in ip
• ipip - ip encapsulation
• encap - ip encapsulation
• iso-tp4 - iso transport protocol class 4
• ospf - open shortest path first
• pup - parc universal packet protocol