This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

FTP tracing

0

Today I did a wireshark capture and seemed to capture everything EXCEPT the FTP activity. I know for a fact that the ftp transaction occurred. Why can't I see it in my pcap file?

asked 27 Jul '17, 15:54

daveschmitzca's gravatar image

daveschmitzca
6112
accept rate: 0%

What are some of the packets in the "everything except" that was captured? Are there any TCP packets, such as HTTP or HTTPS? Or are they just broadcast packets?

Did you do the capture on the FTP server, the FTP client, or some other machine? If it's on the FTP server or client, on which interface did you do the capture - the interface the FTP traffic used, or some other interface, if the machine has that interface? If it's on some other machine, how was that machine connected to the network over which the FTP traffic was sent?

(27 Jul '17, 16:59) Guy Harris ♦♦