I'm using Wireshark 1.4.4 and the remote system is installed with WinPcap rpcapd version (4.1.2). rpcapd.exe -n is running in the remote pc and the corresponding service is ON too. Many options I tried to do a 'remote capture' from Wireshark as below, but nothing seems to be working fine. Interface: Remote & tried the below options rpcap://IPADDRESS/DeviceNPF_{INTERFACE INFORMATION} rpcap://IPADDRESS//DeviceNPF_{INTERFACE INFORMATION} - another try ://IPADDRESS//DeviceNPF_{INTERFACE INFORMATION} - another try & many more tries. In the pop-up window for Host information I tried both the IP & Hostname information with 2002 port & without that also. I have admin rights as well, I'm getting the error "Can't get the list of interfaces: Logon failure - unknown username/pwd (I'm using the domain admin pwd and not local admin- hope this will work). I'm able to telnet to 2002 port on the destination pc. Could any of you provide some clue to make this work? Should I try some other version of WinpCap or Wireshark? Any known issues in capturing remotely? asked 05 Mar '11, 04:27 joes77 edited 05 Mar '11, 04:30 |
4 Answers:
Here's a setup that I use, which you might try (Instructions are based on Windows XP Professional SP3 using Wireshark 1.4.2, and WinPcap 4.1.2): On the machine running the remote packet capture daemon:
On the machine running Wireshark:
*NOTES:
For more information on WinPcap remote packet capturing, try here. answered 07 Mar '11, 19:21 cmaynard ♦♦ |
Did you try this: answered 05 Mar '11, 07:44 joke edited 05 Mar '11, 07:50 |
Sound like a clue, doesn't it? answered 05 Mar '11, 08:07 Jaap ♦ |
Hey Guys, It worked. Wireshark 1.4.4 & rpcap 4.1.0.2001. Not sure why it did not work before, I ran the Wireshark as Admin from a normal user account before. this time i logged in as Admin. May be because of this. Thanks anyways for your help answered 20 Mar '11, 22:35 joes77 edited 20 Mar '11, 22:36 |