I want to capture activities between 192.168.1.10 port 9600(2008 server) and 192.168.1.35 port 9030(Canon copier print server). In Wireshark 1.10.2, under the caption options, then capture filter, what should I type in there? Thanks, Paul asked 14 Oct '13, 11:28 CSA |
One Answer:
If you want to exactly filter on that 4-tuple, the filter would be:
However, the following filter would generally fit your need as well:
As the source port might change between sessions, you might want to drop the "port 9600" part. Then beware of vlan tagging, if you are capturing on a link where vlan tagging is being used, make the filter:
answered 14 Oct '13, 11:57 SYN-bit ♦♦ |