I am new to wireshark and would like to know the easiest way of Filtering all traffic coming and going from a specific IP address on out network. any help would be greatly appreciated. asked 29 Nov '12, 13:34 ksimpson |
One Answer:
You can use a capture filter
or a display filter
You'll find general information about Wiresahrk in the Wiki.
The following videos might also be interesting:
Regards answered 29 Nov '12, 13:55 Kurt Knochner ♦ edited 29 Nov '12, 13:57 |
I have tried that and I am still getting everything not that one specific IP.
what exactly did you try?
the capture filter then the display filter, I did install wireshark on another machine and got the capture filter to work except it is only showing information from the same vlan as the machine i am wanting to watch.
well, that's normal, as you need to setup a proper capturing environment to see traffic of other VLANs and/or other systems.
Basically you need to configure port mirroring on your switch (see link above).