ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] disabling loopback

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Fri, 27 Jan 2012 10:34:05 -0800
On Jan 27, 2012, at 9:53 AM, <Tim.Poth@xxxxxxxxxxx> wrote:

>> On Jan 27, 2012, at 12:46 PM, Andrej van der Zee wrote:
>> 
>> I was wondering if there is a way to prevent packets sent to a local IP address to be shortcut-ed in the kernel. I want them to show up in the tcpdump. How could I do this on Ubuntu?
> 
> http://wiki.wireshark.org/CaptureSetup/Loopback


The relevant part of which is "you can capture on the loopback interface on Linux".

I.e., at least on Linux (and on *BSD and Mac OS X and some other OSes listed there), you *can* capture packets that are shortcutted in the kernel - capture on the loopback interface ("lo" on Linux, "lo0" on *BSD/Mac OS X and at least some of the other OSes).