This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Only seeing Layer 3 messages

0

I purchased a new laptop running windows 7 and installed Wireshark 64 bit version 1.4.0 Everything worked correctly for 3-4 days and now I only see Layer 3 messages. I have made sure there are no filters, all protocols are selected. I have uninstalled and reinstalled and even went to the 32 bit ap. I removed Win PCAP and reinstalled it also. I am at a loss as to what to try next. I can use my old laptop and see all the data but I can not get the new laptop to show everything. Any ideas that I can try?

asked 20 Sep '10, 07:25

8300's gravatar image

8300
1111
accept rate: 0%

edited 26 Sep '10, 01:54

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245


2 Answers:

0

It sounds like your NIC might not be going into promiscuous mode. Are you sure that a) you're running with sufficient privileges to do that (typically administrator), and b) that the "promiscuous mode" box is checked in the capture options?

answered 20 Sep '10, 08:03

jswan's gravatar image

jswan
6112
accept rate: 0%

0

By "only see layer 3 messages" do you mean that you see the TCP connection setup (SYN + SYN/ACK + ACK) but not the actual data? If so this could be due to chimney offloading.

answered 20 Sep '10, 10:48

Gerald%20Combs's gravatar image

Gerald Combs ♦♦
3.3k92258
accept rate: 24%