This is our old Q&A Site. Please post any new questions and answers at

Hi, What is the syntax in the latest Wireshark version to select 2 ip addresses for a capture filter? Thanks. Eric

asked 18 Oct '17, 08:53

ekatow's gravatar image

accept rate: 0%

The syntax is the same as it's always been as it's BPF syntax as shown here.

Do you only want packets between the 2 IP addresses or packets to or from either address?

(18 Oct '17, 09:08) grahamb ♦

Traffic to and from either address

(18 Oct '17, 09:12) ekatow

For example, you want to see all traffic to or from and all traffic to or from, regardless of what host traffic to 192.9.200.{1,2} is coming from and what host traffic from 192.9.200.{1,2} is going to?

(18 Oct '17, 09:25) Guy Harris ♦♦

Ideally, I want to see what is coming from (requests) and what is coming from (responses).

(18 Oct '17, 09:27) ekatow

I.e., you want to see all traffic from and all traffic from

What about traffic to those hosts?

Or do you only want the traffic between and, i.e. packets from to and packets from to, and no packets from or to one of those hosts to or from any third host?

(18 Oct '17, 09:30) Guy Harris ♦♦

only want the traffic between and, i.e. packets from to and packets from to

(18 Oct '17, 09:31) ekatow

Still unclear to me,the filter doesn't know about requests and responses only source and destination. Given hosts of interest, a & b there can be the following types of traffic:

  1. a -> b
  2. b -> a
  3. a -> somewhere other than b
  4. somewhere other than b -> a
  5. b -> somewhere other than a
  6. somewhere other than a -> b
  7. somewhere other than a or b -> somewhere other than a or b

Which of these do you want?

(18 Oct '17, 09:34) grahamb ♦

1 and 2: From a to b. and what b had to say about what a sent.

(18 Oct '17, 09:37) ekatow
showing 5 of 8 show 3 more comments

If you want "packets from to and packets from to", then the capture filter would be

(ip src and ip dst or (ip src and ip dst

You can also use host names, but you'd have to use ip6 rather than ip to check for IPv6 packets.

This will not, however, limit itself to, for example, requests from and responses to those requests from; it will include all packets, whether the ones from happen to be requests or not and whether the ones from happen to be responses or not. All that filter looks at are IP addresses in the IPv4 header (or, for ip6, in the IPv6 header).

permanent link

answered 18 Oct '17, 09:47

Guy%20Harris's gravatar image

Guy Harris ♦♦
accept rate: 19%

If you want traffic in both directions, you could shorten this to "host and host".

(19 Oct '17, 16:27) Jim Aragon
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 18 Oct '17, 08:53

question was seen: 685 times

last updated: 19 Oct '17, 16:27

p​o​w​e​r​e​d by O​S​Q​A