Skip to main content
Version: 7.25

quick


tool/sniffer/quick​

Type: Command

Shows the matching packets live, until you stop it with Q or for the time given in duration. The filter arguments are the filter-* settings of /tool/sniffer without the filter- prefix, and vlan-id for filter-vlan. Without filter arguments, the saved filters apply; with filter arguments, only the filters given apply, and the saved settings do not change. quick cannot run while the sniffer runs (already running). proplist selects the columns, for example proplist=interface,time,dir,src-address,dst-address,protocol,size. See Packet sniffer.

ArgumentTypeDescription
rowsnumMaximum number of packets displayed in the output. Default: the quick-rows setting (20).
show-frameboolWhether to show the raw frame content in the output. Default: the quick-show-frame setting (no).
interfaceobject { interface: iface_enum }Interface or list of interfaces to capture traffic on. A bridged packet shows once on the bridge and once on the bridge port when both are included.
mac-addressobject { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } }Filter: capture only frames with a matching MAC address or MAC address with mask.
src-mac-addressobject { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } }Filter: capture only frames with a matching source MAC address or MAC address with mask.
dst-mac-addressobject { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } }Filter: capture only frames with a matching destination MAC address or MAC address with mask.
mac-protocolobject { mac-protocol-element: super { ! , protocol: alt { mac-protocol: enum () , protocol-number: num [ .. 65535] } } }Filter: capture only frames with a matching MAC (L2) protocol.
ip-protocolobject { ip-protocol-element: super { ! , ip-protocol: enum () } }Filter: capture only packets with a matching IP protocol.
ip-addressobject { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } }Filter: capture only packets with a matching IP address or subnet.
src-ip-addressobject { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } }Filter: capture only packets with a matching source IP address or subnet.
dst-ip-addressobject { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } }Filter: capture only packets with a matching destination IP address or subnet.
ipv6-addressobject { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } }Filter: capture only packets with a matching IPv6 address or prefix.
src-ipv6-addressobject { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } }Filter: capture only packets with a matching source IPv6 address or prefix.
dst-ipv6-addressobject { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } }Filter: capture only packets with a matching destination IPv6 address or prefix.
portobject { port-element: super { ! , port: enum () } }Filter: capture only packets with a matching source or destination port.
src-portobject { port-element: super { ! , port: enum () } }Filter: capture only packets with a matching source port.
dst-portobject { port-element: super { ! , port: enum () } }Filter: capture only packets with a matching destination port.
vlan-idobject { vlan-element: super { ! , vlan: num [ .. 4095] } }Filter: capture only frames with a matching VLAN ID.
directionenum (any | tx | rx) { any:0, tx:1, rx:2 }

Filter: directions to capture.

  • any (default) - Received and sent packets.
  • rx - Received packets. They are captured before the firewall, so packets that a firewall rule drops are still captured.
  • tx - Sent packets, captured after the firewall.
operator-between-entriesenum (or | and) { or:0, and:1 }

How the entries of one filter are combined.

  • or (default) - A packet matches a filter when it matches any of the filter's entries.
  • and - A packet matches a filter only when it matches all of the filter's entries.
cpuobject { cpu-element: super { ! , cpu: num } }Filter: capture only packets processed by the given CPU core.
sizeobject { size-element: super { ! , size-range: range [0 .. 65535] } }Filter: capture only packets with a matching size or size range in bytes.
Read-only ArgumentTypeDescription
interfaceiface_enumInterface on which the packet was captured.
timenumTime offset of the packet relative to the start of the capture, in seconds with microsecond precision.
numnumPacket sequence number, starting from 0 for the first captured packet.
direnum (<- | ->) { <-:0, ->:1 }Direction of the packet, <- received, -> sent.
src-macmacAddrSource MAC address of the frame, shown only for interfaces that have a MAC address, for example Ethernet, WiFi, EoIP, VXLAN or VLAN.
dst-macmacAddrDestination MAC address of the frame, shown only for interfaces that have a MAC address, for example Ethernet, WiFi, EoIP, VXLAN or VLAN.
vlancomposite { id: num [ .. 4095] , priority: num [ .. 7] }VLAN tag of the frame, displayed as id:priority.
src-addresscomposite { address: alt { ip: ipAddr , ipv6: ip6Addr , descr: string } , port: enum () }Source IP address and source port of the packet, displayed as address:port.
dst-addresscomposite { address: alt { ip: ipAddr , ipv6: ip6Addr } , port: enum () }Destination IP address and destination port of the packet, displayed as address:port.
protocolcomposite { mac-protocol: enum () , ip-protocol: enum (ip) { ip:0 } }MAC (L2) protocol of the frame and its IP protocol, for example ip:icmp.
sizenumTotal frame size in bytes, including the L2 header.
cpunumCPU core on which the packet was processed.
fpboolWhether the packet was processed in the fast path.
rawstringRaw frame content in hexadecimal format, shown when the show-frame parameter is enabled.
dscpnumDSCP (Differentiated Services Code Point) field of the IP header.
ecnnumECN (Explicit Congestion Notification) field of the IP header.
fragment-offsetnumFragment offset field of the IP header.
identificationnumIdentification field of the IP header.
ip-header-sizenumSize of the IP header in bytes.
ip-packet-sizenumSize of the IP packet in bytes.
tcp-flagssuper { tcp-flags: multi { array-id, flag: enum (fin | syn | rst | psh | ack | urg | ece | cwr) { fin:0, syn:1, rst:2, psh:3, ack:4, urg:5, ece:6, cwr:7 } } }TCP flags of the packet: fin, syn, rst, psh, ack, urg, ece or cwr.
ttlnumTime to live field of the IP header.