Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Sake Blok <sake@xxxxxxxxxx>
Date: Tue, 1 May 2007 22:22:08 +0200

Hi all,

While analysing a problem today I discovered that I had missed packets in
my session after capturing with a filter like "vlan and host x.x.x.x".
After making a trace with no filter, I could see that packets in one
direction were tagged, while they were not tagged in the other direction.
Then I triesd a filter like "(vlan or not vlan) and host x.x.x.x", but
that just doesn't work.

Does anyone know how to capture both vlan-tagges frames and untagged
frames with an ip-address filter?

Might this be a WinPcap bug?


Cheers,


Sake


Oh BTW, system info is:

Version 0.99.6-SVN-21299 (SVN Rev 21299)

Copyright 1998-2007 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.10.11, with GLib 2.12.11, with WinPcap (version unknown),
with libz 1.2.3, with libpcre 6.4, with Net-SNMP 5.4, with ADNS, with Lua 5.1,
with GnuTLS 1.6.1, with Gcrypt 1.2.3, with MIT Kerberos, with PortAudio
PortAudio V19-devel, with AirPcap.

Running on Windows Server 2003 Service Pack 1, build 3790, with WinPcap version
4.0 (packet.dll version 4.0.0.755), based on libpcap version 0.9.5, without
AirPcap.

Built using Microsoft Visual C++ 6.0 build 8804

Wireshark is Open Source Software released under the GNU General Public License.

Check the man page and http://www.wireshark.org for more information

  • Follow-Ups:
    • Re: [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter
      • From: Jaap Keuter
    • Re: [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter
      • From: Guy Harris
  • Prev by Date: [Wireshark-users] VNC playback
  • Next by Date: Re: [Wireshark-users] RTCP stream analyzed
  • Previous by thread: Re: [Wireshark-users] VNC playback
  • Next by thread: Re: [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation