Just to clarify...
Incoming packets (to INPUT or FORWARD iptables chain) are first seen by on Net_device by tcdump then processed by netfilter/iptables. If packet is forwarded tcpdump can see (just) output of netfilter/iptables.
look here: https://superuser.com/questions/925286/does-tcpdump-bypass-iptables