Install TCPDUMP in ubuntu –
sudo apt-get install tcpdump
sudo yum install tcpdump
sudo tcpdump [options] [filter expression]
sudo tcpdump -i eth1
sudo tcpdump udp
sudo tcpdump port 80
sudo tcpdump dst port 80
sudo tcpdump src host 1.2.3.4
sudo tcpdump “src port 22” and “dst host 1.2.3.4” #Use and or or operator
sudo tcpdump “src port 22” or “src port 443”
tcpdump host 1.2.3.4 -w /home/users/demo/demo.dump
tcpdump -r /home/users/demo/demo.dump #read the raw file