Skip site navigation (1)Skip section navigation (2)

  
 
  

home | help
TCPREPLAY(1)			 Tcpreplay Suite		    TCPREPLAY(1)

NAME
     tcpreplay - Replay network traffic stored in pcap files

SYNOPSIS
     tcpreplay [OPTION]... <pcap_file(s)> | <pcap_dir(s)>

DESCRIPTION
     tcpreplay	is  a  tool  for replaying network traffic from files saved with
     tcpdump or other tools which write pcap(3) files.

     The basic operation of tcpreplay is to resend  all  packets  from	the  in-
     put  file(s)  at the speed at which they were recorded, or a specified data
     rate, up to as fast as the hardware is capable.

     Optionally, the traffic can be split between  two	interfaces,  written  to
     files,  filtered  and  edited  in various ways, providing the means to test
     firewalls, NIDS and other network devices.

     On Linux, raw IP (layer 3 only) interfaces such as WireGuard  and	tun  are
     supported automatically: any layer 2 header in the input file (Ethernet in-
     cluding  VLAN  tags,  Linux SLL, loopback, ...) is stripped and packets are
     sent as bare IPv4/IPv6. Non-IP packets such as ARP cannot be sent on  these
     interfaces and are reported as failed.

     For    more    details,	please	  see	 the	Tcpreplay   Manual   at:
     http://tcpreplay.appneta.com

OPTIONS
     -r, --portmap=string
	 Rewrite TCP/UDP ports. May appear up to 9999 times.

	 Specify a list of comma delimited port mappings consisting of colon de-
	 limited port number pairs. Each colon delimited port pair  consists  of
	 the port to match followed by the port number to rewrite.

	 Examples:

	     --portmap=80:8000 --portmap=8080:80    # 80->8000 and 8080->80
	     --portmap=8000,8080,88888:80	    # 3 different ports become 80
	     --portmap=8000-8999:80		    # ports 8000 to 8999 become 80

     -s, --seed=number
	 Randomize  src/dst  IPv4/v6 addresses w/ given seed. Cannot be combined
	 with: --fuzz-seed.

	 Causes the source and destination IPv4/v6 addresses to be  pseudo  ran-
	 domized  but still maintain client/server relationships. Since the ran-
	 domization is deterministic based on the seed, you can reuse  the  same
	 seed value to recreate the traffic.

     -N, --pnat=string
	 Rewrite  IPv4/v6  addresses using pseudo-NAT. May appear up to 2 times.
	 Cannot be combined with: --srcipmap.

	 Takes a comma delimited series of colon delimited CIDR netblock  pairs.
	 Each  netblock  pair is evaluated in order against the IP addresses. If
	 the IP address in the packet matches the first netblock, it is  rewrit-
	 ten using the second netblock as a mask against the high order bits.

	 IPv4 Example:

	     --pnat=192.168.0.0/16:10.77.0.0/16,172.16.0.0/12:10.1.0.0/24

	 IPv6 Example:

	     --pnat=[2001:db8::/32]:[dead::/16],[2001:db8::/32]:[::ffff:0:0/96]

     -S, --srcipmap=string
	 Rewrite  source  IPv4/v6 addresses using pseudo-NAT. Cannot be combined
	 with: --pnat.

	 Works just like the --pnat option, but only affects the source  IP  ad-
	 dresses in the IPv4/v6 header.

     -D, --dstipmap=string
	 Rewrite  destination IPv4/v6 addresses using pseudo-NAT. Cannot be com-
	 bined with: --pnat.

	 Works just like the --pnat option, but only affects the destination  IP
	 addresses in the IPv4/v6 header.

     -e, --endpoints=string
	 Rewrite   IP	addresses   to	 be  between  two  endpoints.  Requires:
	 --cachefile.

	 Takes a pair of colon delimited IPv4/v6 addresses which will be used to
	 rewrite all traffic to appear to be between the two IP addresses.

	 IPv4 Example:

	     --endpoints=172.16.0.1:172.16.0.2

	 IPv6 Example:

	     --endpoints=[2001:db8::dead:beef]:[::ffff:0:0:ac:f:0:2]

     --tcp-sequence=number
	 Change TCP Sequence (and ACK) numbers /w given seed. Range: 1	to  any.
	 Default: 0.

	 Change  all  TCP sequence numbers, and related sequence-acknowledgement
	 numbers. They will be shifted by a random amount based on the	provided
	 seed.

     -b, --skipbroadcast
	 Skip rewriting broadcast/multicast IPv4/v6 addresses.

	 By  default  --seed,  --pnat and --endpoints will rewrite broadcast and
	 multicast IPv4/v6 and MAC  addresses.	 Setting  this	flag  will  keep
	 broadcast/multicast IPv4/v6 and MAC addresses from being rewritten.

     -C, --fixcsum
	 Force recalculation of IPv4/TCP/UDP header checksums.

	 Causes  each  IPv4/v6	packet	to have their checksums recalculated and
	 fixed. Automatically enabled for packets modified with --seed,  --pnat,
	 --endpoints or --fixlen.

     --fixhdrlen
	 Alter IP/TCP header len to match packet length.

	 By  default,  tcpreplay  will	send  packets  with  the original packet
	 length, However, you may want the  packet  length  revised  to  minimum
	 packet size. Using this option, tcpreplay will rewrite (fix) the packet
	 length,  and recalculate checksums when packet length changes. Caution:
	 undesired packet changes may occur when this option is specified.

     -m, --mtu=number
	 Override default MTU length (1500 bytes). Range: 1 to MAX_SNAPLEN.

	 Override the default 1500 byte MTU size  for  determining  the  maximum
	 padding length (--fixlen=pad) or when truncating (--mtu-trunc).

     --mtu-trunc
	 Truncate packets larger then specified MTU.

	 Similar  to  --fixlen,  this  option will truncate data in packets from
	 Layer 3 and above to be no larger then the MTU.

     -E, --efcs
	 Remove Ethernet checksums (FCS) from end of frames.

	 Note, this option is pretty dangerous! We do not actually check to  see
	 if  a FCS actually exists in the frame, we just blindly delete the last
	 4 bytes. Hence, you should only use this if you know know that your  OS
	 provides the FCS when reading raw packets.

     --ttl=string
	 Modify the IPv4/v6 TTL/Hop Limit.

	 Allows  you  to  modify  the  TTL/Hop Limit of all the IPv4/v6 packets.
	 Specify a number to hard-code the value or +/-value to increase or  de-
	 crease by the value provided (limited to 1-255).

	 Examples:

	     --ttl=10
	     --ttl=+7
	     --ttl=-64

     --tos=number
	 Set the IPv4 TOS/DiffServ/ECN byte. Range: 0 to 255.

	 Allows  you  to  override the TOS (also known as DiffServ/ECN) value in
	 IPv4.

     --tclass=number
	 Set the IPv6 Traffic Class byte. Range: 0 to 255.

	 Allows you to override the IPv6 Traffic Class field.

     --flowlabel=number
	 Set the IPv6 Flow Label. Range: 0 to 1048575.

	 Allows you to override the 20bit IPv6 Flow Label field. Has  no  effect
	 on IPv4 packets.

     -F, --fixlen=string
	 Pad or truncate packet data to match header length.

	 Packets  may be truncated during capture if the snaplen is smaller then
	 the packet. This option allows you to modify  the  packet  to	pad  the
	 packet back out to the size stored in the IPv4/v6 header or rewrite the
	 IP header total length to reflect the stored packet length.

	 pad
	     Truncated	packets  will  be  padded  out so that the packet length
	     matches the IPv4 total length

	 trunc
	     Truncated packets will have their IPv4 total length field rewritten
	     to match the actual packet length

	 del
	     Delete the packet

     --fuzz-seed=number
	 Fuzz 1 in X packets. Edit bytes, length, or emulate packet drop. Range:
	 0 to any. Default: 0.

	 This fuzzing was designed as to test layer 7  protocols  such	as  voip
	 protocols.  It  modifies  randomly  1	out  of  X  packets  (where  X =
	 --fuzz-factor) in order for stateful protocols to cover more  of  their
	 code. The random fuzzing actions focus on data start and end because it
	 often	is  the  part of the data application protocols base their deci-
	 sions on.

	 Possible fuzzing actions list: * drop packet *  reduce  packet  size  *
	 edit packet Bytes:

		* Not all Bytes have the same probability of appearance in real life.
		  Replace with 0x00, 0xFF, or a random byte with equal likelihood.
		* Not all Bytes have the same significance in a packet.
		  Replace the start, the end, or the middle of the packet with equal likelihood.

	 *   do nothing (7 out of 8 packets)

     --fuzz-factor=number
	 Set  the Fuzz 1 in X packet ratio (default 1 in 8 packets). Range: 1 to
	 any. Default: 8. Requires: --fuzz-seed.

	 Sets the ratio of for --fuzz-seed option. By default this value  is  8,
	 which	means 1 in 8 packets are modified by fuzzing. Note that this ra-
	 tio is based on the random number generated by the supplied fuzz  seed.
	 Therefore by default you cannot expect that exactly every eighth packet
	 will be modified.

     --skipl2broadcast
	 Skip rewriting broadcast/multicast Layer 2 addresses.

	 By default, editing Layer 2 addresses will rewrite broadcast and multi-
	 cast MAC addresses.	 Setting this flag will keep broadcast/multicast
	 MAC addresses from being rewritten.

     --dlt=string
	 Override output DLT encapsulation.

	 By  default, no DLT (data link type) conversion will be made. To change
	 the DLT type of the output pcap, select one of the following values:

	 enet
	     Ethernet aka DLT_EN10MB

	 hdlc
	     Cisco HDLC aka DLT_C_HDLC

	 jnpr_eth
	     Juniper Ethernet DLT_C_JNPR_ETHER

	 pppserial
	     PPP Serial aka DLT_PPP_SERIAL

	 user
	     User specified Layer 2 header and DLT type

     --enet-dmac=string
	 Override destination ethernet MAC addresses.

	 Takes a pair of comma deliminated ethernet MAC addresses which will re-
	 place the destination MAC address of outbound packets.  The  first  MAC
	 address  will be used for the server to client traffic and the optional
	 second MAC address will be used for the client to server traffic.

	 Example:

	     --enet-dmac=00:12:13:14:15:16,00:22:33:44:55:66

     --enet-smac=string
	 Override source ethernet MAC addresses.

	 Takes a pair of comma deliminated ethernet MAC addresses which will re-
	 place the source MAC address of outbound packets. The first MAC address
	 will be used for the server to client traffic and the	optional  second
	 MAC address will be used for the client to server traffic.

	 Example:

	     --enet-smac=00:12:13:14:15:16,00:22:33:44:55:66

     --enet-subsmac=string
	 Substitute MAC addresses. May appear up to 9999 times.

	 Allows you to rewrite ethernet MAC addresses of packets. It takes comma
	 delimited  pair  or  MACs  address  and rewrites all occurrences of the
	 first MAC with the value of the second MAC. Example:

	     --enet-subsmac=00:12:13:14:15:16,00:22:33:44:55:66

     --enet-mac-seed=number
	 Randomize  MAC  addresses.  Cannot  be  combined   with:   --enet-smac,
	 --enet-dmac, --enet-subsmac.

	 Allows  you to randomize ethernet MAC addresses of packets, mostly like
	 what --seed option does for IPv4/IPv6 addresses.

     --enet-mac-seed-keep-bytes=number
	 Randomize MAC addresses. Range: 1 to 6. Requires: --enet-mac-seed.

	 Keep some bytes untouched when usinging --enet-mac-seed option.

     --enet-vlan=string
	 Specify ethernet 802.1q VLAN tag mode.

	 Allows you to rewrite ethernet frames to add a 802.1q header  to  stan-
	 dard 802.3 ethernet headers or remove the 802.1q VLAN tag information.

	 add
	     Adds  an  802.1q VLAN header to the existing 802.3 ethernet header.
	     If a VLAN header already exists, a new VLAN header is added outside
	     of the existing header.

	     Note that you will be allowed to run this option multiple times  to
	     create  more  than  2  VLAN  headers, however those packets will be
	     valid. At most you should have 2 X 802.1q VLAN tags,  or  outer  an
	     802.1ad and an inner 802.1q VLAN tag.

	 del
	     Rewrites  the  existing  802.1q  VLAN  header  as an 802.3 ethernet
	     header

     --enet-vlan-tag=number
	 Specify the new ethernet 802.1q VLAN tag value. Range: 0 to  4095.  Re-
	 quires: --enet-vlan.

	 Mandatory  when --enet-vlan=add is used on packets that are not already
	 VLAN tagged.

     --enet-vlan-cfi=number
	 Specify the ethernet 802.1q VLAN CFI value. Range: 0  to  1.  Requires:
	 --enet-vlan.

	 When  omitted,  the  CFI bit of an existing VLAN header is preserved; a
	 newly added tag on a  previously  untagged  packet  defaults  to  0  (a
	 one-time notice is printed).

     --enet-vlan-pri=number
	 Specify  the  ethernet  802.1q  VLAN priority. Range: 0 to 7. Requires:
	 --enet-vlan.

	 When omitted, the priority of an existing VLAN header is  preserved;  a
	 newly	added  tag  on	a  previously  untagged  packet defaults to 0 (a
	 one-time notice is printed).

     --enet-vlan-proto=string
	 Specify VLAN tag protocol 802.1q or 802.1ad.

	 Allows you to specify the protocol of the added VLAN tags.

	 802.1q
	     Specifies that 802.1q VLAN headers are to be added. This is the de-
	     fault.

	 802.1ad
	     Specifies that 802.1ad Q-in-Q VLAN headers are to be added. To make
	     valid packets, input packets must already have 802.1q VLAN headers.

     --hdlc-control=number
	 Specify HDLC control value.

	 The Cisco HDLC header has a 1 byte  "control"	field.	Apparently  this
	 should always be 0, but if you can use any 1 byte value.

     --hdlc-address=number
	 Specify HDLC address.

	 The  Cisco HDLC header has a 1 byte "address" field which has two valid
	 values:

	 0x0F
	     Unicast

	 0xBF
	     Broadcast

     You can however specify any single byte value.

     --user-dlt=number
	 Set output file DLT type.

	 Set the DLT value of the output pcap file.

     --user-dlink=string
	 Rewrite Data-Link layer with user specified data. May appear  up  to  2
	 times.

	 Provide  a series of comma deliminated hex values which will be used to
	 rewrite or create the Layer 2 header of the packets. The first instance
	 of this argument will rewrite both server and client  traffic,  but  if
	 this  argument  is  specified	a  second  time, it will be used for the
	 client traffic.

	 Example:

	     --user-dlink=01,02,03,04,05,06,00,1A,2B,3C,4D,5E,6F,08,00

     -d, --dbug=number
	 Enable debugging output. Range: 0 to 5. Default: 0.

	 If configured with --enable-debug, then you  can  specify  a  verbosity
	 level for debugging output. Higher numbers increase verbosity.

     -q, --quiet
	 Quiet mode.

	 Print nothing except the statistics at the end of the run

     -T, --timer=string
	 Select packet timing mode: select, ioport, gtod, nano. Default: gtod.

	 Allows you to select the packet timing method to use:

	 nano
	     Use nanosleep() API

	 select
	     Use select() API

	 ioport
	     Write to the i386 IO Port 0x80

	 gtod [default]
	     Use a gettimeofday() loop

     --maxsleep=number
	 Sleep for no more then X milliseconds between packets. Default: 0.

	 Set  a limit for the maximum number of milliseconds that tcpreplay will
	 sleep between packets. Effectively prevents long delays between packets
	 without effecting the majority of packets. Default is disabled.

     -v, --verbose
	 Print decoded packets via tcpdump to STDOUT.

     -A, --decode=string
	 Arguments passed to tcpdump decoder. Requires: --verbose.

	 When enabling verbose mode (-v) you may also specify one or more  addi-
	 tional   arguments to pass to tcpdump to modify the way packets are de-
	 coded. By default, -n and -l are used. Be  sure  to quote the arguments
	 like: -A "-axxx" so that they are not interpreted by tcpreplay.  Please
	 see the tcpdump(1) man page for a complete list of options.

     -K, --preload_pcap
	 Preloads packets into RAM before sending.

	 This  option  loads  the  specified pcap(s) into RAM before starting to
	 send in order to improve replay performance while introducing a startup
	 performance hit. Preloading can be used with or  without  --loop.  This
	 option  also suppresses flow statistics collection for every iteration,
	 which can significantly reduce memory usage. Flow statistics  are  pre-
	 dicted  based	on  options  supplied  and statistics collected from the
	 first loop iteration.

     -c, --cachefile=string
	 Split traffic via a tcpprep cache file. Requires:  --intf2.  Cannot  be
	 combined with: --dualfile.

	 If  you  have	a pcap file you would like to use to send bi-directional
	 traffic through a device (firewall, router, IDS, etc) then  using  tcp-
	 prep  you  can create a cachefile which tcpreplay will use to split the
	 traffic across two network interfaces.

     -2, --dualfile
	 Replay two files at a time from a network tap. Requires: --intf2.  Can-
	 not be combined with: --cachefile.

	 If  you  captured network traffic using a network tap, then you can end
	 up with two pcap files- one for each direction. This option will replay
	 these two files at the same time, one on each interface  and  inter-mix
	 them using the timestamps in each.

     -i, --intf1=string
	 Client  to  server/RX/primary	traffic output interface. This option is
	 required.

	 Required network interface used to send either all traffic  or  traffic
	 which	is  marked  as 'primary' via tcpprep. Primary traffic is usually
	 client-to-server or inbound (RX) on khial virtual interfaces.

     -I, --intf2=string
	 Server to client/TX/secondary traffic output interface.

	 Optional network interface used to send  traffic  which  is  marked  as
	 'secondary'  via tcpprep. Secondary traffic is usually server-to-client
	 or outbound (TX) on khial virtual interfaces. Generally, it only  makes
	 sense to use this option with --cachefile.

     -w, --write=string
	 Pcap file to receive traffic outputs. Cannot be combined with: --intf2.

	 Optional pcap file name used to receive traffic.

     --include=string
	 Send only selected packet numbers. Cannot be combined with: --exclude.

	 Override  default  of processing all packets stored in the capture file
	 and only send packets that are part of a supplied list of  packet  num-
	 bers.

	     -x P:1-5,9,15,72-

	 would skip packets 1 through 5, the 9th and 15th packet, and packets 72
	 until the end of the file

     --exclude=string
	 Send  all  but  selected packet numbers. Cannot be combined with: --in-
	 clude.

	 Override default of processing all packets stored in the  capture  file
	 and  only  send  packets that are NOT part of a supplied list of packet
	 numbers.

	     -x P:1-5,9,15,72-

	 would skip packets 1 through 5, the 9th and 15th packet, and packets 72
	 until the end of the file

     --listnics
	 List available network interfaces and exit.

     -l, --loop=number
	 Loop through the capture file X times. Range: 0 to any. Default: 1.

     --loopdelay-ms=number
	 Delay between loops in milliseconds. Range: 0 to any. Default:  0.  Re-
	 quires: --loop. Cannot be combined with: --loopdelay-ns.

     --loopdelay-ns=number
	 Delay	between  loops	in nanoseconds. Range: 0 to any. Default: 0. Re-
	 quires: --loop. Cannot be combined with: --loopdelay-ms.

	 By default, tcpreplay will use loop  delay  with  microsecond	accuracy
	 (loopdelay-ms). In order to use loop delay with nanosecond accuracy you
	 need to use nano packet timing mode.

     --pktlen
	 Override the snaplen and use the actual packet len.

	 By  default,  tcpreplay  will	send  packets  based  on the size of the
	 "snaplen" stored in the pcap file which is usually the correct thing to
	 do. However, occasionally, tools will store more bytes then told to. By
	 specifying this option, tcpreplay will ignore the snaplen field and in-
	 stead try to send packets based on  the  original  packet  length.  Bad
	 things may happen if you specify this option.

     -L, --limit=number
	 Limit the number of packets to send. Range: 1 to any. Default: -1.

	 By default, tcpreplay will send all the packets. Alternatively, you can
	 specify a maximum number of packets to send.

     --duration=number
	 Limit the number of seconds to send. Range: 1 to any. Default: -1.

	 By default, tcpreplay will send all the packets. Alternatively, you can
	 specify a maximum number of seconds to transmit.

     -x, --multiplier=string
	 Modify  replay  speed	to  a  given  multiple. Cannot be combined with:
	 --pps, --mbps, --oneatatime, --topspeed.

	 Specify a value to modify the packet replay speed. Examples:

		 2.0 will replay traffic at twice the speed captured
		 0.7 will replay traffic at 70% the speed captured

     -p, --pps=string
	 Replay packets at a given packets/sec. Cannot be combined with:  --mul-
	 tiplier, --mbps, --oneatatime, --topspeed.

	 Specify   a   value  to  regulate  the  packet  replay  to  a	specific
	 packet-per-second rate. Examples:

		 200 will replay traffic at 200 packets per second
		 0.25 will replay traffic at 15 packets per minute

     -M, --mbps=string
	 Replay packets at a given Mbps. Cannot be combined with:  --multiplier,
	 --pps, --oneatatime, --topspeed.

	 Specify  a floating point value for the Mbps rate that tcpreplay should
	 send packets at.

     -t, --topspeed
	 Replay packets as fast as possible. Cannot be	combined  with:  --mbps,
	 --multiplier, --pps, --oneatatime.

     -o, --oneatatime
	 Replay  one  packet  at  a time for each user input. Cannot be combined
	 with: --mbps, --pps, --multiplier, --topspeed.

	 Allows you to step through one or more packets at a time.

     --pps-multi=number
	 Number of packets to send for each time interval. Range: 1 to any.  De-
	 fault: 1. Requires: --pps.

	 When  trying  to send packets at very high rates, the time between each
	 packet can be so short that it is impossible to  accurately  sleep  for
	 the  required	period	of time. This option allows you to send multiple
	 packets at a time, thus allowing for longer sleep times  which  can  be
	 more accurately implemented.

     --loss=string
	 Simulate random percent packet loss (0-100).

	 Set  to a percentage between 0 and 100 to simulate packet loss at send.
	 Loss is random: each packet is independently  dropped	with  the  given
	 probability, not on a fixed pattern (e.g. not every Nth packet), so the
	 actual  number  dropped  will vary slightly run to run. Dropped packets
	 are not sent and are not counted as failed.

	 Examples:

		 25 will drop approximately one quarter of packets, chosen at random
		 100 will drop every packet (nothing will be sent)

     --unique-ip
	 Modify IP addresses each loop iteration to generate unique  flows.  Re-
	 quires: --loop. Cannot be combined with: --seed, --fuzz-seed.

	 Ensure  IPv4 and IPv6 packets will be unique for each --loop iteration.
	 This is done in a way that will not alter  packet  CRC,  and  therefore
	 will  generally  not affect performance. This option will significantly
	 increase the flows/sec over generated over multiple loop iterations.

     --unique-ip-loops=string
	 Number of times to loop  before  assigning  new  unique  ip.  Requires:
	 --unique-ip.

	 Number of --loop iterations before a new unique IP is assigned. Default
	 is 1. Assumes both --loop and --unique-ip.

     --netmap
	 Write packets directly to netmap enabled network adapter.

	 This  feature	will  detect netmap capable network drivers on Linux and
	 BSD systems. If detected, the network driver is bypassed for the execu-
	 tion duration, and network buffers will be written  to  directly.  This
	 will  allow  you  to  achieve	full  line  rates  on  commodity network
	 adapters, similar to rates achieved by commercial network traffic  gen-
	 erators.  Note that bypassing the network driver will disrupt other ap-
	 plications connected through the test interface. See INSTALL  for  more
	 information.

	 This  feature	can  also  be  enabled	by  specifying	an  interface as
	 'netmap:<intf>' or 'vale:<intf>. For  example	'netmap:eth0'  specifies
	 netmap over interface eth0.

     --nm-delay=number
	 Netmap startup delay. Default: 10.

	 Number  of  seconds to delay after netmap is loaded. Required to ensure
	 interfaces are fully up before netmap transmit. Requires netmap option.
	 Default is 10 seconds.

     --no-flow-stats
	 Suppress printing and tracking flow count, rates and expirations.

	 Suppress the collection and printing of flow  statistics.  This  option
	 may improve performance when not using --preload-pcap option, otherwise
	 its only function is to suppress printing.

	 The  flow  feature  will  track and print statistics of the flows being
	 sent. A flow is loosely defined as a unique combination of  a	5-tuple,
	 i.e.  source IP, destination IP, source port, destination port and pro-
	 tocol.

	 If --loop is specified, the flows from one iteration to the  next  will
	 not  be  unique,  unless  the	packets  are altered. Use --unique-ip or
	 tcpreplay-edit to alter packets between iterations.

     --flow-expiry=number
	 Number of inactive seconds before a flow is considered expired.  Range:
	 0 to any. Default: 0. Cannot be combined with: --no-flow-stats.

	 This  option  will  track and report flow expirations based on the flow
	 idle times. The timestamps within the pcap file are used  to  determine
	 the  expiry,  not the actual timestamp of the packets are replayed. For
	 example, a value of 30 suggests that if no traffic is seen  on  a  flow
	 for  30 seconds, any subsequent traffic would be considered a new flow,
	 and thereby will increment the flows and flows per second (fps) statis-
	 tics.

	 This option can be used to optimize  flow  timeout  settings  for  flow
	 products.  Setting the timeout low may lead to flows being dropped when
	 in fact the flow is simply slow to respond. Configuring your flow time-
	 outs too high may increase resources required by your flow product.

	 Note that using this option while replaying  at  higher  than	original
	 speeds can lead to inflated flows and fps counts.

	 Default is 0 (no expiry) and a typical value is 30-120 seconds.

     -P, --pid
	 Print the PID of tcpreplay at startup.

     --stats=number
	 Print	statistics  every  X  seconds, or every loop if '0'. Range: 0 to
	 any.

	 Note that timed delays are a "best  effort"  and  long  delays  between
	 sending  packets may cause equally long delays between printing statis-
	 tics.

     -W, --suppress-warnings
	 suppress printing warning messages.

     --xdp
	 Write packets directly to AF_XDP enabled network adapter.

	 This feature will detect AF_XDP capable network drivers on  Linux  sys-
	 tems  that  have  'libxdp-dev' and 'libbpf-dev' installed. If detected,
	 the network stack is bypassed and packets are sent directly to an  eBPF
	 enabled driver directly. This will allow you to achieve full line rates
	 on  commodity network adapters, similar to rates achieved by commercial
	 network traffic generators.

     --xdp-queue=number
	 Which of the adapter's queues to bind the AF_XDP socket to. Range: 0 to
	 4095. Default: 0. Requires: --xdp.

	 An AF_XDP socket is bound to a single hardware queue. Queue 0	is  used
	 by  default;  on  a  multi-queue  adapter you may need a different one,
	 since the queue must exist on the adapter and traffic steering may  not
	 use queue 0. If the queue does not exist the socket cannot be created.

     --xdp-no-fallback
	 Fail  instead	of  falling  back  when AF_XDP is unavailable. Requires:
	 --xdp.

	 By default, if an AF_XDP socket cannot be set up on the interface - the
	 driver has no XDP support at all, or the requested queue does not exist
	 - tcpreplay warns and replays using its default  injection  method  in-
	 stead	of  failing.  Use  this to make that case a hard error, which is
	 what you want when benchmarking: a silent change  of  injection  method
	 would change what is being measured.

     --io-uring
	 Send packets asynchronously via Linux io_uring.

	 This  feature is available on Linux systems with a kernel that supports
	 io_uring and 'liburing-dev' installed. Packets are still sent through a
	 PF_PACKET raw socket, but sends are submitted asynchronously through an
	 io_uring submission queue, which reduces  per-packet  syscall	overhead
	 and  lets the kernel process transmissions while tcpreplay prepares the
	 next packet.

     --raw
	 Send packets via a PF_INET raw IP socket instead of PF_PACKET.

	 By default, tcpreplay injects packets with PF_PACKET, which writes  di-
	 rectly  to  the  network  driver  below  the  IP  stack. This means lo-
	 cally-generated netfilter/iptables rules (and anything else hooked into
	 the normal Linux IP stack) never see the traffic, even  when  replaying
	 it on the same host that has those rules configured.

	 This option instead sends each packet's IP header and payload through a
	 PF_INET  raw  IP  (SOCK_RAW)  socket  bound  to  the interface given by
	 --intf1/--intf2, so the kernel's normal IP stack --  including  netfil-
	 ter/iptables -- processes it like any other locally-generated packet.

	 The  trade-off is L2 fidelity: the kernel builds its own Ethernet fram-
	 ing for the outgoing packet, so the  source/destination  MAC  addresses
	 from  the  capture  are  not reproduced, and only IPv4 packets are cur-
	 rently supported. This option is Linux-only  and  requires  appropriate
	 privileges to open a raw socket (typically root or CAP_NET_RAW).

     -V, --version
	 Print version information.

     -h, --less-help
	 Display less usage information and exit.

     -H, --help
	 Display usage information and exit.

     --more-help
	 Pass the extended usage information through a pager.

     --save-opts[=string]
	 Save the current option state to a config file.

     --load-opts=string, --no-load-opts
	 Load options from a config file; --no-load-opts disables this.

OPTION PRESETS
     Any  option  that is not marked as not presettable may be preset by loading
     values from configuration ("RC" or ".INI") file(s). The homerc file is $$/,
     unless that is a directory; in  that  case  .tcpreplayrc  is  searched  for
     within it.

FILES
     See OPTION PRESETS for configuration files.

EXIT STATUS
     One of the following exit values will be returned:

     0 (EXIT_SUCCESS)
	 Successful program execution.

     1 (EXIT_FAILURE)
	 The operation failed or the command syntax was not valid.

     66 (EX_NOINPUT)
	 A specified configuration file could not be loaded.

     70 (EX_SOFTWARE)
	 libopts  had  an  internal  operational  error.  Please  report  it  to
	 autogen-users@lists.sourceforge.net. Thank you.

AUTHORS
     Copyright 2013-2026 Fred Klassen - AppNeta by Broadcom

     Copyright 2000-2012 Aaron Turner

     For support please use the tcpreplay-users@lists.sourceforge.net mailing
     list.

     The latest version of this software is always available from:
     http://tcpreplay.appneta.com/

COPYRIGHT
     Copyright (C) 2000-2026 Aaron Turner and Fred Klassen, all rights reserved.
     This program is released under the terms of the GNU General Public License,
     version 3 or later.

BUGS
     Please send bug reports to: tcpreplay-users@lists.sourceforge.net

NOTES
     This manual page was generated from the tcpreplay option definitions.

Tcpreplay Suite 		   2026-08-14			    TCPREPLAY(1)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=tcpreplay-edit&sektion=1&manpath=FreeBSD+Ports+15.1.quarterly>

home | help