This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

WireShark to just scan my LAN

0

New to WireShark. At times on our LAN at work the Internet slows to a crawl, goes intermittent, or out completely. I would like for WireShark to be able to just capture my LAN to see what node is hogging the bandwidth. If I can rule out my LAN, then I can call my ISP to see if the trouble is on their end. My work domain / LAN is part of a much larger forest. We are all connected via MPLS lines. I need WireShark to just capture my LAN and not the entire corporation. We are in 35 countries. I don't see an area within the WireShark config where I can tell it to just capture from my Router and or Switch. I ran WireShark as is and it just kept going and going and was displaying some IP's that are not on my network. That led me to believe it is capturing everything from my location, and our sister locations.

asked 11 Mar '15, 12:44

Everest63's gravatar image

Everest63
6113
accept rate: 0%

edited 11 Mar '15, 12:45


One Answer:

1

Wireshark will only capture the traffic that "hits" your network adapter, which is

  • traffic that was generated by your system (yes, that might contain "foreign" addresses as well, if you talk to google.com or others).
  • traffic that was sent to your system if you are running a service on the system
  • broadcast and multicast traffic for the local network

So, unless you are talking to systems in other locations, you won't see those IP addresses in your capture file.

Please read the Wiki for more information about packet capturing

https://wiki.wireshark.org/CaptureSetup/Ethernet

To answer your question:

I would like for WireShark to be able to just capture my LAN to see what node is hogging the bandwidth.

You'll have to capture the traffic in front of your internet router (LAN side - see Switch mirror port in the wiki link above) and capture traffic there.

Regards
Kurt

answered 12 Mar '15, 01:18

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 12 Mar '15, 02:19

Hi

I've same problem and also i am new on wireshark. I've followed your advice but i'm not able to view the bandwidth usage from others ip on my lan. With the captured packets i can't be shure how is used my lan at work's time.

Can you helpme?

(29 Jul '15, 02:58) reikidude