# 先進到/tmp 目錄執行,方便Filezila 傳輸
# 開啟抓包
nohup tcpdump -i eth0 -s0 -nnA 'port 22' -w dump22.pcap &
[1] 15022
# 查詢pid
ps -ef|grep tcpdump |grep -v 'grep'
# 結束抓包
kill 15022
參考
https://www.cnblogs.com/bonelee/p/6121821.html
https://www.cnblogs.com/chyingp/p/linux-command-tcpdump.html