I am trying to capture only the EAPOL packets from my WLAN. I have read on the CaptureFilters wiki page that this should work with:
But when i put that into wireshark it does not capture anything.
So i played with the display filters, i think the equivalet there is:
which also shows nothing on a data set that definitely contains EAPOL packets. Instead i could just set:
as the display filter and it works perfectly, the right packets show up.
Is it possible to set that somehow as capture filter? Bug in Wireshark or wrong filter?
asked 03 Jan '16, 13:59
edited 03 Jan '16, 14:02
I use ether proto 0x888e as a capture filter in Windump or tcpdump, such as:
but it's really only good for the 4-way WPA handshake. Group rekeys are encrypted, so tougher to get. Share your trace and we can have a look. Exactly where do you put this filter when configuring?
If it is a trace with 802.11 headers, this will likely not work. Try:
Without capture filter:
With Capture filter in place:
answered 03 Jan '16, 15:10
edited 04 Jan '16, 05:13