Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Sake Blok <sake@xxxxxxxxxx>
Date: Mon, 19 Nov 2007 22:10:30 +0100

On Mon, Nov 19, 2007 at 11:49:26AM -0600, Brian Swan wrote:
>  
> I've had a problem for a while now with my laptop and wireshark/WinPCap.  
> If I configure a mirror port on a switch, and sniff the traffic, all I 
> ever get is broadcasts (under windows).  

Is the "Capture packets in promiscuous mode" checkbox checked when you open
the Capture Options dialog? If it's not, the NIC will only forward unicasts
that were addressed to the NIC in your machine and multicast/broadcast 
frames to WinPcap.

Hope this helps,  Cheers,


Sake

  • Follow-Ups:
    • Re: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
      • From: Guy Harris
  • References:
    • [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
      • From: Brian Swan
  • Prev by Date: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
  • Next by Date: Re: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
  • Previous by thread: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
  • Next by thread: Re: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not what you think! :)
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation