This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have set up a statiion to capture WiFi data with Wireshark. The station is a Ubuntu laptop with a TP-Link TP-WN722M WiFi adaptor. The WiFi network interface is configured to capture in monitor mode and Wireshark in promiscuous mode.

I want to filter all traffic from a particular WiFi chip manufacture. I know its ID in the first 24bits of the MAC address, such as AA:BB:CC:xx:xx:xx. How can I set the filter?

Thank you. :)

asked 18 Aug '14, 21:13

garypty's gravatar image

garypty
31337
accept rate: 0%


From the 7th example on Wiresjhark Display Filters :

"The "slice" feature is also useful to filter on the vendor identifier part (OUI) of the MAC address, see the Ethernet page for details. Thus you may restrict the display to only packets from a specific device manufacturer. E.g. for DELL machines only:

  eth.src[0:3]==00:06:5B

(Note: this is a display filter not a capture filter)

It appears that a capture filter of the form ether[6:3] == 0xnnnnnn should also work (altho I haven't tried it).

permanent link

answered 18 Aug '14, 21:31

Bill%20Meier's gravatar image

Bill Meier ♦♦
3.2k1850
accept rate: 17%

edited 18 Aug '14, 21:50

As I am capturing WiFi data, the fitler is wlan.sa[0:3]==00:06:5B . Thanks.

(19 Aug '14, 03:53) garypty
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×157
×134

question asked: 18 Aug '14, 21:13

question was seen: 16,677 times

last updated: 19 Aug '14, 03:53

p​o​w​e​r​e​d by O​S​Q​A