I need to analyze a traffic-dump on my network to check if all the PCs have enabled tcp keep-live features.
I'm using tcpdump for that purpose.
What I need to know is if there is a possibility to filter for only the keep-alive packets.
On windows I see that wireshark can do that, but on my linux system, which has only console mode, I didn't know how filter that sort of packet.
Best Answer
A keepalive probe is a packet with no data in it and the ACK flag turned on
what this does:
Disclaimer: not actually tested, but should point you in a good direction
NOTE: breakdown of the tcpdump filter to make it more readable. probably can take out the first set of parens.