This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have a Network Video Recorder connected to an IP camera on a Cisco 3750 switch. I wanted to sniff the traffic between the recorder and the camera so I mirrored (using SPAN) the camera port (FA1/0/23) to my PC port (FA1/0/9). Then I run wireshark on my PC in promiscuous mode expected to capture all packets between the recorder and the camera but all I see is arp and broadcast traffic!! Based on the activity led, there's lot of traffic on the mirrored port but nothing is being captured by wireshark. What am I doing wrong?

asked 13 Oct '15, 10:28

dyue's gravatar image

dyue
45114
accept rate: 100%


Thank you for those who viewed this question but I found the answer within these thousands of posted answers. It turned out that I had left my antivirus and firewall on the PC I was using. Disable Bitdefender and now I am seeing everything.

permanent link

answered 13 Oct '15, 10:55

dyue's gravatar image

dyue
45114
accept rate: 100%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×69
×24

question asked: 13 Oct '15, 10:28

question was seen: 2,464 times

last updated: 13 Oct '15, 10:55

p​o​w​e​r​e​d by O​S​Q​A