This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

hello

how i can write right caputre filter to pick all the traffic except the follow mac addresses?

asked 24 Oct '17, 02:11

scanman's gravatar image

scanman
16335
accept rate: 0%


The capture filter for a MAC address is in the form of ether host xx:xx:xx:xx:xx:xx where x is a hexadecimal digit.

To combine multiple addresses and then exclude them, firstly "or" them together and then negate the entire list, e.g.

!(ether host 12:34:56:78:9A:BC or aa:bb:cc:dd:ee:ff or ff:ff:ff:ff:ff:ff)
permanent link

answered 24 Oct '17, 04:48

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Depending on your exact requirements it would be something like this:

not ether host 00:01:02:03:04:05 and not ether host 00:06:07:08:09:0A

but you can check the Wiki for more details.

permanent link

answered 24 Oct '17, 04:35

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

thank you alot )

(24 Oct '17, 04:51) scanman
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×184
×40

question asked: 24 Oct '17, 02:11

question was seen: 984 times

last updated: 24 Oct '17, 04:59

p​o​w​e​r​e​d by O​S​Q​A