ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] Capture Filter not working Display filter works

From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Thu, 20 Nov 2008 11:00:01 -0500


Sebastian Richter wrote:
Dear all,

I have a problem with the WIreshark capture Filter.
OS: Ubuntu 8.10
Wireshark 1.0.3

I have the PCs NIC connected to the Monitor Port of an Switch and without capture filter I receive all traffic without any problem.

No I want to use �port 5060 or ether proto 0xc021� to capture SIP traffic and link control protocol packets.

Wireshark didn�t complain about anything is starting the trace, when now maching traffic is coming in I will see nothing and it is also nothing stored in the capturefile on my HDD.

Is the traffic coming in on VLANs? In that case to use capture filters you need to prefix the filter "vlan" to the filter. See the section on capture filters here:

http://wiki.wireshark.org/CaptureSetup/VLAN