Hi, I have the following assignment. My problem is that when I type in ether in the filter, it turns red. Is that supposed to happen? When I type in ether src and then my mac address, it still doesn't work. Am I doing something wrong? Any help is appreciated. Thanks.
Examples of capture filters (replace the MAC address with the one you find in step 2)
ether dst 00:25:00:41:96:62
ether src 00:25:00:41:96:62
multicast and not ether dst ff:ff:ff:ff:ff:ff
broadcast and ether dst ff:ff:ff:ff:ff:ff asked 08 Dec ‘13, 19:40 heisenberg55 |
One Answer:
Let me just give you a hint... Please read about 'Capture Filters' and 'Display Filters' in the Wireshark documentation. They are different; each type is entered in a different place in the GUI. (A web search for 'wireshark "display filter" "capture filter"' will also give lots of info). answered 08 Dec '13, 19:59 Bill Meier ♦♦ |
Thanks for the response. I looked around and found the codes eth.src and eth.dst. Maybe the code was wrong on the assignment or maybe I have a newer or older version of wireshark?
Again: I'm going to suggest that you do some reading & research to understand the difference between a "capture filter" and a "display filter" in Wireshark. :)
The syntax and verbs, etc used for each are different and are entered in different places in the GUI.
Your assignment specifically mentions using a "capture filter".
I figured it out! I was supposed to use capture options. Thanks for the help. I appreciate it.