This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How do I configure Wireshark to capture ONLY the handshake packets?

0

Using TCP as a filter does not do that as it still shows TLS and few other protocols. I just want to show someone the 3-way handshake process packets without anything else

asked 19 May '15, 04:34

matka's gravatar image

matka
6112
accept rate: 0%


One Answer:

0

Do you need a capture filter, or will a display filter work for you? It's hard (if not impossible) to capture the third packet of the three way handshake with a filter, because you need TCP session tracking to determine which ACK is the third packet of a handshake.

A display filter can do it with a little trick though. If you can live with display filtering, take a look at this blog post:

https://blog.packet-foo.com/2015/03/advanced-display-filtering/

answered 19 May '15, 05:59

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%