$ 0 0 Do you know what "ip and (not ip[1] & 0xfc == 0x0)" means? After reading this article on Wireshark capture filters, you will.