Capture/Sniff Traffic using tcpdump / wireshark

If you want to record a pcap (for port 21, 65000 and 65500 on iface eth1) file (for reading/displaying it with e.g. wireshark), you can simply run:

tcpdump -i eth1 port 21 or port 65000 or port 65500 -s0 -w outputfile.pcap