I currently have wireshark installed on my windowsXP box; I want to do a capture between a remote laptop and a remote file server on the same subnet. How can I set that up? thanks!
asked 19 Oct '10, 10:27
edited 19 Oct '10, 10:28
I think what you want to do is capture the traffic between the laptop and the file server with the help of your XP box, which would be a pretty standard setup. I wouldn't call that a remote capture, because for me that would imply doing a rcapd capture, which is a little more complicated.
What you have to do is to attach your XP box to the same switch either server or laptop (or both) are physically attached to, and then setup a monitoring (a.k.a SPAN) session to forward their packets towards the switch port your XP box is attached to. For this you will need a manageable switch and access to the CLI or Web front end where the monitoring settings can be configured. If you don't have that kind of switch you can try using a hub that you put inline, or go for a low cost switch tap sold by Dual-Comm.
answered 19 Oct '10, 15:43