This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

exclude remote desktop connection packets

0

Hi, I'm doing some network test, capturing packets in my PC and a the same time in a server which I connect to via Remote Desktop Connection (windows 7), this generates a lot of traffic, how can I set a filter to exclude the traffic due to the remote destkop connection?

asked 29 Oct '15, 06:45

rok's gravatar image

rok
26446
accept rate: 0%


One Answer:

1

Capture filter: "not tcp port 3389", assuming you're running RDP on the standard port.

If you connect to the server via RDP and then run Wireshark on the server, Wireshark should automatically apply that capture filter for you on the server. See the section titled "Default Capture Filters" on this page.

answered 29 Oct '15, 07:08

Jim%20Aragon's gravatar image

Jim Aragon
7.2k733118
accept rate: 24%