Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] Capture Filter not work for hub, seems like a bug?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Tao Zhou <moonese@xxxxxxxxx>
Date: Tue, 25 Aug 2009 14:41:34 +0800

Hi, All:

I need to capture the packets going through a STB box for diagnosis purpose, 
so just make my laptop (Windows XP) and STB at the same hub, however I found a problem about capture filter, 
If I don't set the capture filter, all traffic going through the hub can be captured, including those to STB, on ports including http(80) and other ports;
However if I set a Capture Filter "port 80", no packets captured anymore.
It seems to me that if the Capture Filter is set, only packets to the laptop NIC IP address is captured, and those to STB is dropped.

So now I just leave the capture filter empty, and use *display filter* to filter out those http packets.
It works fine, except that the packets are in a quite large volumn, since no filter in capture level...

Is this a Wireshark bug, or I just missed something?



  • Prev by Date: Re: [Wireshark-dev] behavior of tcp_dissect_pdus when protocol pdu is across tcp segments
  • Next by Date: Re: [Wireshark-dev] [Wireshark-commits] rev 29523: /trunk/ /trunk/epan/dissectors/: packet-tcp.c /trunk/epan/: column-utils.c column-utils.h column.c column_info.h prefs.c /trunk/gtk/: new_packet_list.c
  • Previous by thread: Re: [Wireshark-dev] behavior of tcp_dissect_pdus when protocol pdu is across tcp segments
  • Next by thread: [Wireshark-dev] Output from tshark
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation