This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hey guys, I am new to wireshark and having some problems.

I am trying to capture some packets on my personal computer and i go to url and type int a web address like facebook.com and when i go to look for syn packets i cant find just the syn packet. It has syn,ack and there is non with the source as my ip. I know there has to be one. Please help.

asked 03 Feb '14, 08:21

zerotolerance's gravatar image

zerotolerance
1112
accept rate: 0%

Ok i fixed the problem. It was my VPN software that was blocking everything.

(03 Feb '14, 09:24) zerotolerance

i cant find just the syn packet.

If there is really only the SYN frame, it could be due to TCP/IP offloading. See the following link.

http://ask.wireshark.org/questions/13131/wireshark-does-not-capture-packets-w-payloads

However, as you say that you can see SYN-ACK frames, what do you see, if you right click the SYN frame and then select "Follow TCP stream"?

Is it possible to post the capture file somewhere (google drive, dropbox, cloudshark.org)?

Regards
Kurt

permanent link

answered 03 Feb '14, 08:34

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 03 Feb '14, 08:36

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×184
×178
×40

question asked: 03 Feb '14, 08:21

question was seen: 1,811 times

last updated: 03 Feb '14, 09:24

p​o​w​e​r​e​d by O​S​Q​A