Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Capturing packets on dial-up connections

From: "Darren Mease" <Darren.Mease@xxxxxxxxxxxxxxxx>
Date: Wed, 22 Nov 2006 10:11:29 -0000
Hi Guy,

That's great, cheers.  Tested with Windump and got same results.  I was
running WinPCap 4.0 Alpha, and have gone to Beta2.  All working now.

Cheers for the help!

-----Original Message-----
From: Guy Harris [mailto:guy@xxxxxxxxxxxx] 
Sent: 21 November 2006 18:28
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Capturing packets on dial-up connections

Darren Mease wrote:

> I am trying to capture packets when dialling up, and can select the 
> interface, that shows the correct IP and that it is capturing packets.

> However, when looking at the packets, all I get is a long list of:
> 
>  
> 
> Ethern [Packet size limited during capture]

Ethernet?  That means you're probably doing this on Windows.

If so, try doing a capture with WinDump and with the "-s 0" flag (to 
ensure that WinPcap isn't deliberately limiting the packet size during 
capture) and the "-w" flag to write it in binary format to a file, and 
then try reading the file.  ("windump -D" will list the interfaces, with

names and numbers; the number given for an interface in the output of 
"windump -D" can be used as an argument to the "-i" flag to get WinDump 
to capture on that interface.)

Then try reading that file with Wireshark; if you get the same problem, 
this is almost certainly a WinPcap issue - report it to the WinPcap 
developers:

	http://www.winpcap.org/bugs.htm

In step 5, report, in addition to all that information, any special 
networking software you might be running (firewalls, VPN software,
etc.).

If you're not doing this on Windows, please tell us what version of what

operating system you're using.
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users 
-- 
 
 
 
 
 
 
 
  
 
 
 
Darren Mease 
Security Operations Engineer 
Boxing Orange Ltd  
t: 0871 871 2774 
f: 0871 871 0068  
 
Darren.Mease@xxxxxxxxxxxxxxxx 
http://www.boxingorange.com/ 
 
This message (and any associated files) is intended only for the  
use of the individual or entity to which it is addressed and may  
contain information that is confidential, subject to copyright or 
constitutes a trade secret. If you are not the intended recipient  
you are hereby notified that any dissemination, copying or  
distribution of this message, or files associated with this message,  
is strictly prohibited. If you have received this message in error,  
please notify us immediately by replying to the message and deleting  
it from your computer. Messages sent to and from us may be monitored.  
 
Internet communications cannot be guaranteed to be secure or error-free  
as information could be intercepted, corrupted, lost, destroyed, arrive  
late or incomplete, or contain viruses. Therefore, we do not accept  
responsibility for any errors or omissions that are present in this  
message, or any attachment, that have arisen as a result of e-mail  
transmission. If verification is required, please request a hard-copy  
version. Any views or opinions presented are solely those of the author  
and do not necessarily represent those of the company.