This is our old Q&A Site. Please post any new questions and answers at

Hi, I have Wireshark monitoring a TAP-Win32 Adapter connection installed with Cyberghost but the traffic doesn't show up as encrypted. Is this normal? And how do I check if traffic is encrypted through VPN. This happens with ProXPN also.

Many thanks

asked 12 Dec '10, 23:55

fh67's gravatar image

accept rate: 0%

Yes, that is normal. If you capture on a virtual adapter that is used for a VPN connection you will see unencrypted packets in and out. The encryption happens when the virtual TAP adapter passes the data over to your physical network card. To see the encrypted traffic you need to capture on your "real" network card (wired or wireless) and you should see lots of encrypted packets.

In fact you can go and capture both with two Wireshark instances at the same time and then see how the unencrypted packets on the TAP adapter correlate to the physical adapter.

permanent link

answered 13 Dec '10, 05:30

Jasper's gravatar image

Jasper ♦♦
accept rate: 18%

edited 13 Dec '10, 05:31

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 12 Dec '10, 23:55

question was seen: 24,721 times

last updated: 13 Dec '10, 05:31

p​o​w​e​r​e​d by O​S​Q​A