Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Wireshark only capturing TCP handshake

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Tue, 04 Mar 2008 22:20:33 +0100

Hi,

Let me ask you: The firewall is on the troubled platform? And this firewall has rules for incoming non-local connections? Bet your firewall is interfering in the network stack.

Thanx,
Jaap

John Temples wrote:
I'm trying to capture some incoming HTTP connections with Wireshark
0.99.8 on a Windows Server 2003 system.  The only thing Wireshark
captures is the three packets in the three-way handshake of the TCP
connection; no other packets related to the connection are captured.
However, the connection completes successfully.  No capture filter is
active in Wireshark.

When running Wireshark on the PC that originates the connection, the
entire transaction is successfully captured on the originating PC.

When the connection originates from a PC on the same LAN as the
Windows 2003 Server system, Wireshark on the Windows 2003 Server
system successfully captures the entire transaction.

The problem only occurs when the connection originates from the
Internet.  The LAN in question has a SonicWALL firewall with no
special configuration.

What could cause Wireshark not to see the entire connection?

--
John W. Temples, III


  • Follow-Ups:
    • Re: [Wireshark-users] Wireshark only capturing TCP handshake
      • From: John Temples
    • Re: [Wireshark-users] Wireshark only capturing TCP handshake
      • From: Gianluca Varenni
  • References:
    • [Wireshark-users] Wireshark only capturing TCP handshake
      • From: John Temples
  • Prev by Date: [Wireshark-users] Wireshark only capturing TCP handshake
  • Next by Date: Re: [Wireshark-users] tShark SSL Decryption Issue
  • Previous by thread: [Wireshark-users] Wireshark only capturing TCP handshake
  • Next by thread: Re: [Wireshark-users] Wireshark only capturing TCP handshake
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation