Quickstart¶
This walks through the whole loop: inspect a capture, replay it, control its speed, then rewrite it for a different target. Budget about five minutes.
Replay puts real packets on a real network
tcpreplay injects live traffic onto the interface you give it. It needs
root (raw sockets), and the packets it sends are the actual packets from
the capture — with whatever MACs, IPs and ports they contain.
Do not replay onto a production network, and never onto the interface you are connected through (for example, your SSH link). Use an isolated lab segment, a spare NIC, or a virtual network. To experiment with zero risk of disturbing anything, replay onto a dummy interface (see below).
Throughout, replace eth0 with your test interface.
1. Get a capture¶
You can use any pcap file. To make your own from live traffic:
Or grab one of the sample captures. The rest
of this page assumes a file named sample.pcap.
2. Inspect it¶
Before sending anything, see what's in the file:
tcpcapinfo decodes the pcap's own structure — link-layer type, snap length,
byte order, per-packet lengths — which is exactly what you need to know before
replaying or rewriting. See tcpcapinfo.
3. Replay at the original speed¶
The default behaviour is to reproduce the capture's own inter-packet timing:
When it finishes, you get a report:
Actual: 1000 packets (486400 bytes) sent in 9.89 seconds
Rated: 49180.0 Bps, 0.393 Mbps, 101.10 pps
Statistics for network device: eth0
Successful packets: 1000
Failed packets: 0
Truncated packets: 0
Retried packets (ENOBUFS): 0
4. Control the speed¶
The same packets, sent at whatever pace your test calls for:
--topspeed (or -t) ignores the capture's timing and sends flat-out.
Add --loop 100 to send the file 100 times, or --loop 0 to loop forever.
For the full timing model, see
Timing & speed control.
Warm the cache for high-rate tests
Add --preload-pcap (-K) to load the entire file into memory before
sending. This removes disk I/O from the send loop and is essential for
accurate line-rate benchmarks. See
Performance & line-rate testing.
5. Rewrite it for a different target¶
Say you want to replay this capture at a device that expects different
addresses. tcprewrite edits the file without sending anything:
$ tcprewrite --infile=sample.pcap --outfile=retargeted.pcap \
--enet-dmac=00:11:22:33:44:55 \
--pnat=10.0.0.0/8:192.168.0.0/16 \
--fixcsum
That rewrites the destination MAC, maps the 10.0.0.0/8 network onto
192.168.0.0/16, and recalculates checksums. Now replay the rewritten file:
Rewrite and replay in one pass
If your build includes tcpreplay-edit, you can skip the intermediate file
and pass tcprewrite's options straight to the replay command:
See Rewriting packet headers for the full set of edits.
Practising safely on a dummy interface¶
To run every command above with no chance of touching a real network, create a Linux dummy interface and replay onto that:
$ sudo ip link add dummy0 type dummy
$ sudo ip link set dummy0 up
$ sudo tcpreplay -i dummy0 --topspeed sample.pcap # goes nowhere, but exercises the full path
Remove it when you're done:
Where to next¶
- The tools — what each command is for.
- How-to guides — real testing recipes.
- Concepts — how it all fits together.