Shayne O'Neill wrote: | I might have to. The system is on a hub (yeah, I know) with 2 other | servers, and has a ssh session incoming. How would I do that without all | that data? Tcpdump can filter based on IP addresses and port numbers. I can't remember the syntax though, it's something I have to consult the man page for every time I do it. Cameron.