This is our old Q&A Site. Please post any new questions and answers at

I use wireshark 1.6.2 version. i switch Mirror port capature packet. I find capature fileter: arp . But no packet, in Promiscuoous mode.This is a error!

Wireshark: Summary Time First packet: 1970-01-01 08:00:00 Last packet: 1970-01-01 08:00:00 Elapse: 00:00:00

Capture capture filter: arp

Traffice packets: 0

asked 25 Oct '11, 08:42

zhoutree's gravatar image

accept rate: 0%

edited 25 Oct '11, 09:44

Guy%20Harris's gravatar image

Guy Harris ♦♦

我发现别的抓包程序都可以设置成 arp or port 5246捕获过滤。 但是wireshark 设置居然一个包都没有。 我是在交换机镜像端口抓包的。

(25 Oct '11, 08:46) zhoutree

hope to modify it.
can to capture arp

(25 Oct '11, 08:47) zhoutree

Is there a VLAN on this network?

If so, try

(arp or port 5246) or (vlan and (arp or port 5246))
(25 Oct '11, 09:43) Guy Harris ♦♦

very thanks! Mirro port is VLAN network

vlan and (arp or port 5246) work very much. in Promiscuous mode!

permanent link

answered 26 Oct '11, 02:22

zhoutree's gravatar image

accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 25 Oct '11, 08:42

question was seen: 3,011 times

last updated: 26 Oct '11, 02:22

p​o​w​e​r​e​d by O​S​Q​A