IP src and dst
- ip.src==
- ip.dst==
IPv6 RA message
- icmpv6.type==134
IPv6 RS message
- icmpv6.type==133
DHCP packet
- udp.port eq67 || udp.port eq 68
- bootp
- dhcpv6
Samba service
- smb
DHCP relay
- bootp.hw.mac_addr == 00:90:00:00:06:01
http method
- http.request.method==post
filter ipv6 packets
- not.ip.version==6
ICMP v6
- icmpv6.type=128 ping request
- icmpv6.type=129 ping reply
IPv6 PMD
- ipv6.fragment.offset(Fragmentation packets)
Filter unnecessary packets
- !(arp or dns or icmp)
Troubleshoot tcp session
- tcp.analysis.flags
- tcp.flags == 0x0002 <=syn
- tcp.flags == 0x0012 <=syn.ack
Search content key word
- tcp contains facebook
- udp contains facebook