This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

DHCP broadcast packets not displayed

0

Hello,

I'm tracing on a TAP the connection of a machine. I want to see the DHCP exchange of this machine. Normally I expect to see the sequence Discover - Offer - Request - Ack. But I see only Offer and Ack, the broadcast messages sent from the machine are not displayed. I tried several Wireshark Version from 1.6 to 1.10 with different WinPcap (4.1.2 / 4.1.3) also 32 Bit and 64 Bit versions and different Network Ports/cards on the PC. If I connect the TAP to a XP Laptop I see the full sequence but on the PC I don't see them. The Windows Firewall is disabled and no additional one is installed. The capture run in promiscous mode without any capture filter.

The PC I have to use is an HP 8300 under Win7-64 with an additional 2 Port Ethernet Card from HP. I tried the Port of the cards and also the internal Port on the mainboard without success.

asked 20 Jun '13, 03:00

thaloss's gravatar image

thaloss
11112
accept rate: 0%


One Answer:

0

I tried the Port of the cards and also the internal Port on the mainboard without success.

Please try to disable the TCP/IP "binding" of the capturing adapter.

Interface Properties -> remove check mark at "Internet Protocol Version V4" (and V6).

Regards
Kurt

answered 20 Jun '13, 03:17

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Thanks, I tried it but no change, still only Offer and Ack visible.

regards

Thaloss

(20 Jun '13, 04:03) thaloss

What kind of TAP is it (brand, modell)?

Can you try to use a switch mirror port instead of the TAP, to rule out the TAP as a possible source of the problem?

However, I think you already checked that, right?

If I connect the TAP to a XP Laptop I see the full sequence but on the PC I don't see them.

So, the problem occurs only if your capturing system is Windows 7, right?

If so, is there any security software installed on that system (AV, Firewall, Endpoint Secuirty, VPN Client)? If yes, please disable/uninstall that piece of software and try again.

(20 Jun '13, 04:20) Kurt Knochner ♦