Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] filtering on Ethernet MAC OUI

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Sake Blok" <sake@xxxxxxxxxx>
Date: Thu, 2 Apr 2009 07:29:55 +0200

That would also match 00:10:00:21:91:aa:bb, better use "eth.addr[0:3] == 00:21:91"

Cheers,
Sake

----- Original Message ----- From: "Wes" <wes_r@xxxxxxxxx>
To: "Community support list for Wireshark" <wireshark-users@xxxxxxxxxxxxx>
Sent: Wednesday, April 01, 2009 11:46 PM
Subject: Re: [Wireshark-users] filtering on Ethernet MAC OUI



Here is one way:

eth.addr contains 00:21:91

Wes

--- On Wed, 4/1/09, noah davids <ndav1@xxxxxxx> wrote:

From: noah davids <ndav1@xxxxxxx>
Subject: [Wireshark-users] filtering on Ethernet MAC OUI
To: Wireshark-users@xxxxxxxxxxxxx
Date: Wednesday, April 1, 2009, 7:27 AM







Is there any way to filter on just
the Ethernet MAC OUI?
I've tried data [0:2] but that only does the data and
there does not appear to
be a frame [0:2].


Noah Davids
=+=+=+=+=+=+=+=+=+=+=+=+=+=+
Serendipity
is a function of bandwidth


-----Inline Attachment Follows-----

___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users

mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe



___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe




  • References:
    • Re: [Wireshark-users] filtering on Ethernet MAC OUI
      • From: Wes
  • Prev by Date: Re: [Wireshark-users] Wireshark-users Digest, Vol 35, Issue 1
  • Next by Date: Re: [Wireshark-users] [Bug 3360]Wiresharkgivesdecodingerrorduring rnsap messagedissection
  • Previous by thread: Re: [Wireshark-users] filtering on Ethernet MAC OUI
  • Next by thread: [Wireshark-users] filtering on Ethernet MAC OUI
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation