Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] I see no captured packets at all

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Small, James" <JSmall@xxxxxxxxxxxxxx>
Date: Tue, 2 Jan 2007 09:17:29 -0500

Yep--that's it.  Thanks Guy.

Also, just for the record, I tried capturing under WinPcap under XP, SP2
both using the Microsoft Bridge and just using my wireless adapter in
non-promiscuous mode (Intel Pro Wireless 2200BG built-in to a Dell
Latitude D610).

My particular wireless card will only capture if I don't enable
promiscuous mode.  Interestingly enough, if I don't have the Microsoft
Bridge installed with the wireless card as a bridge adapter, then I
won't see multicast traffic groups that my host didn't join (in other
words I don't see most multicast traffic).  Once I setup the Microsoft
Bridge, then I can capture normally (using promiscuous mode) using the
bridge and all multicast traffic shows up using either the bridge or the
wireless card (although still must capture on wireless card with
promiscuous mode off).

Note that in any case, I can not see non-broadcast/non-multicast traffic
which is not destined to my wireless card.  For this you would need the
AirPcap adapter.

--Jim

> -----Original Message-----
> From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-
> bounces@xxxxxxxxxxxxx] On Behalf Of Guy Harris
> Sent: Friday, December 29, 2006 3:17 PM
> To: Community support list for Wireshark
> Subject: Re: [Wireshark-users] I see no captured packets at all
> 
> Small, James wrote:
> 
> > Unfortunately, many wireless cards in Windows do not allow you to do
> > network captures.  I use to have a link to a web site that explained
it
> > all and had a list of Wireless NICs/Chipsets and which ones worked
or
> > didn't work for network captures but now I can't find it.
> 
> You might be thinking of
> 
> 	http://www.micro-logix.com/WinPcap/Supported.asp
> 
> which is linked to from
> 
> 	http://wiki.wireshark.org/CaptureSetup/WLAN
> 
> which gives information on wireless captures on various OSes,
including
> Windows (and also mentions the AirPcap adapter).
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users

  • Follow-Ups:
    • Re: [Wireshark-users] I see no captured packets at all
      • From: Hans Nilsson
  • Prev by Date: [Wireshark-users] captured file can not be understood by Tshark
  • Next by Date: Re: [Wireshark-users] VoIP compatible Software
  • Previous by thread: Re: [Wireshark-users] captured file can not be understood by Tshark
  • Next by thread: Re: [Wireshark-users] I see no captured packets at all
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation