Wireshark-users: Re: [Wireshark-users] Capture Filter not work for hub, seems like a bug?
From: Tao Zhou <[email protected]>
Date: Wed, 26 Aug 2009 09:41:33 +0800
Yes, the only thing I do is to use "port 80" as Capture Filter, the checkbox of "Capture packets in promiscuous mode" is always on.


From: Martin Visser <[email protected]>
Date: Wed, 26 Aug 2009 07:23:16 +1000

At a first guess, do you have "promiscuous" mode turned on in the capture options? It will need to be.

Regards, Martin

[email protected]

On Tue, Aug 25, 2009 at 12:05 PM, Tao Zhou <[email protected]> wrote:
Hi, All:

I need to capture the packets going through a STB box for diagnosis purpose, 
so just make my laptop (Windows XP) and STB at the same hub, however I found a problem about capture filter, 
If I don't set the capture filter, all traffic going through the hub can be captured, including those to STB, on ports including http(80) and other ports;
However if I set a Capture Filter "port 80", no packets captured anymore.
It seems to me that if the Capture Filter is set, only packets to the laptop NIC IP address is captured, and those to STB is dropped.

So now I just leave the capture filter empty, and use *display filter* to filter out those http packets.
It works fine, except that the packets are in a quite large volumn, since no filter in capture level...

Is this a Wireshark bug, or I just missed something?