很不错
1. tshark + wireshark+ssh
ssh root@HOST tcpdump -U -s0 -w - 'not port 22' | wireshark -k -i -
2. tcpdump + wireshark + ssh
ssh root@server.com 'tshark -f "port !22" -w -' | wireshark -k -i -
3. fifo方式
mkfifo /tmp/fifo; ssh-keygen; ssh-copyid root@remotehostaddress; sudo ssh root@remotehost "tshark -i eth1 -f 'not tcp port 22' -w -" > /tmp/fifo &; sudo wireshark -k -i /tmp/fifo;