Wireshark

  • Riverbed Technology
  • WinPcap
SHARKFEST '13 - Wireshark Developer and User Conference - June 16-19, 2013 - UC Berkeley
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: ketzal devims <ketzaldevims@xxxxxxxxx>
Date: Mon, 21 Sep 2009 22:23:22 +0200

But I'm using Wireshark exactly on the same computer.
I removed Windows XP to put Ubuntu 9.04...

Best regards
Louis

2009/9/21 Jaap Keuter <jaap.keuter@xxxxxxxxx>
Hi,

That depends on the network card, driver and network stack. Windows is notorious
for not showing VLAN info. See http://wiki.wireshark.org/CaptureSetup/VLAN

Thanx,
Jaap

ketzal devims wrote:
> Hi Stephen, I forgot a question:
>
> Why is there this problem on linux and not on Windows Wireshark version?
>
> Best Regards
> Louis
>
> 2009/9/21 Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx
> <mailto:steve@xxxxxxxxxxxxxxxxxx>>
>
>
>     On Sep 21, 2009, at 1:14 PM, ketzal devims wrote:
>
>      > I’m able to see these packets without filter... Why can’t I see them
>      > with th filter?
>      >
>      > Some friend told me it's a libpcap problem. The libpcap version in
>      > my computer is 1.0.0-1 (almost the last one)
>      >
>      > What's going on??? I really don't understand.
>
>     A common cause of this seems to be when you have 802.1q VLAN tags
>     coming into the machine and being passed up into Wireshark.  If this
>     is the case, you would need to use "vlan and <your filter>".
>
>
>     Steve
>

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe

  • Follow-Ups:
    • Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
      • From: Jaap Keuter
  • References:
    • [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
      • From: ketzal devims
    • Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
      • From: Stephen Fisher
    • Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
      • From: ketzal devims
    • Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
      • From: Jaap Keuter
  • Prev by Date: Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
  • Next by Date: Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
  • Previous by thread: Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
  • Next by thread: Re: [Wireshark-users] [Ubuntu-Wireshark1.2.2-SIP] I cannot see some packets with a basic capture filter and I'm able to see them without the filter...
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation