Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Capture Filter not working Display filter works

From: "Sebastian Richter" <sr@xxxxxxxx>
Date: Thu, 20 Nov 2008 11:09:08 +0100

Dear all,

I have a problem with the WIreshark capture Filter.

OS: Ubuntu 8.10

Wireshark 1.0.3

 

I have the PCs NIC connected to the Monitor Port of an Switch and without capture filter I receive all traffic without any problem.

 

No I want to use “port 5060 or ether proto 0xc021” to capture SIP traffic and link control protocol packets.

Wireshark didn’t complain about anything is starting the trace, when now maching traffic is coming in I will see nothing and it is also nothing stored in the capturefile on my HDD.

 

Could it be that I have to add some options during Wireshark start up or that I have to install an advanced libpcap or so?

 

-          Tracing without Capture Filter is possible.

-          Capture filter for mac address is also working

 

Thanks for your help.

 

Sebastian