i'm sure there was a filter expression with the Meraki packet captures to capture a range of ports, can anybody confirm the expression required to capture a range, for example lets say i want to capture only Microsoft teams audio i would want to filter on this port range,
expression, "port range 50000 to 50019" is what i would logically assume but is not correct, can anyone advise.
Pro tip; capture far more than you want, and then limit it in Wireshark afterwards using a display filter.
For example, I'd be tempted to use a capture filter of something like "udp" to capture all UDP traffic, and then narrow it down afterwards.
Often you'll find something unusual and want to see what else was happening around that time, or was there some other trigger, and you want to be able to just see those extra packets without doing another capture.
Thanks Philip, the problem i had with that is Meraki limits the duration to 1200 seconds (20minutes) or 100,000 packets and even filtering on UDP it runs for around 25 seconds and ive hit the 100,000 packets allready which is why i needed a more specific expression for the range i was looking at.