Wireshark中过滤特定结尾IP地址的方法求助
Hey there! Let's ditch those 9 messy filter lines and simplify this with a clean, precise rule. Here's how to target exactly the IPs you care about:
Core Universal Filter (Matches Source OR Destination IPs)
Use this one-liner to capture any traffic where either the source or destination IP ends in .60 or .61:
ip.addr & 0xff == 60 || ip.addr & 0xff == 61
How it works:
ip.addr: Targets both source and destination IP fields in packets& 0xff: Performs a bitwise AND to isolate the last byte of the IP address (since0xffis 8 bits of 1s, this strips off the first three octets)== 60 || == 61: Matches only IPs where that last byte is 60 or 61
Scenario-Specific Filters
If you only need to filter one direction of traffic, tweak the rule:
- Filter only source IPs:
ip.src & 0xff == 60 || ip.src & 0xff == 61 - Filter only destination IPs:
ip.dst & 0xff == 60 || ip.dst & 0xff == 61
Bonus: Narrow to a Specific Subnet (If Applicable)
If all your target IPs share a common prefix (e.g., 192.168.5.x), you can combine the last-byte check with a subnet filter to avoid accidental matches from other networks:
(ip.addr >= 192.168.5.60 && ip.addr <= 192.168.5.61)
Or using CIDR notation (works for contiguous ranges):
ip.addr == 192.168.5.60/31
(Note: /31 is a valid CIDR for pairs of consecutive IPs in IPv4)
This approach is way more maintainable than listing individual IPs, and it won't catch unintended addresses like your previous multi-line filter was doing.
内容的提问来源于stack exchange,提问作者Christopher Cass

