Hi Sake,

Thanks a lot for your prompt reply.
I already tried the following options

1. (host or (vlan and (host
2. (net or (vlan and (net

In both the above cases I am facing the same error, I can see only
incoming traffic. Where as with out these filters I can see both
incoming & outgoing traffic.
Is this behavior is because of unidirectional L2 tagging?


> When I am doing live capture with Wireshark using the "Capture filter"
option (host, my expectation is that I can able to see
both the to and from (source & dest) traffic with that ip address. But I
can see only incoming traffic (i.e. destination ip address only), it is
not showing any outgoing traffic from that ip address.
> If I remove that filter and start capturing, then I can see both
incoming and outgoing traffic with that ip address.
> I am doubting some setup problem in my Wireshark, but not sure where
to change.
> Can you please help me on this issue.

It could be that incoming traffic is not 802.1Q tagged, while outgoing
traffic is  802.1Q tagged, that all depends on where you are doing the
capture and what the L2 design is of that infrastructure.

The capture filter "host" will only match untagged
traffic. If you would also like to see the 802.1Q tagged traffic for, you need to specify a capture filter like this:

"host or (vlan and host"

Please note that the order in that filter is important. See also:

Hope this helps,


PS  This can also happen on PPPoE networks or any other situation where
L2 tagging/encapsulation is done in one direction, but the most common
case is 802.1Q vlan-tagging

