Hello. I'm trying to capture the traffic one one port and mirror that traffic to the other. I'm using an HP ProCurve 2810-24G switch, I've set up the Port Monitoring option through the web configuration. Now for the WireShark, it looks as though it's only showing the traffic on the PC running wireshark, as opposed to showing me the mirrored traffic on the PC being monitored.
Is there some sort of adjustment that has to be made on WireShark to output only the traffic from the monitored port?
asked 03 Oct '12, 08:31
Normally it should just work if you set the mirror port correctly (which I usually double check, especially if the results are strange like yours) - maybe you've got source and destination ports mixed up. If the mirror session is correct, Wireshark will capture anything that the network card receives unless:
By the way, I'd usually disable all protocols on the capture card to avoid the card sending and receiving any traffic for itself - in Windows you can just uncheck all protocols on the card properties dialog.
answered 03 Oct '12, 08:55