I use wireshark 1.6.2 version. i switch Mirror port capature packet. I find capature fileter: arp . But no packet, in Promiscuoous mode.This is a error! Wireshark: Summary Time First packet: 1970-01-01 08:00:00 Last packet: 1970-01-01 08:00:00 Elapse: 00:00:00 Capture capture filter: arp Traffice packets: 0 asked 25 Oct '11, 08:42 zhoutree edited 25 Oct '11, 09:44 Guy Harris ♦♦ |
One Answer:
very thanks! Mirro port is VLAN network vlan and (arp or port 5246) work very much. in Promiscuous mode! answered 26 Oct '11, 02:22 zhoutree |
我发现别的抓包程序都可以设置成 arp or port 5246捕获过滤。 但是wireshark 设置居然一个包都没有。 我是在交换机镜像端口抓包的。
hope to modify it.
can to capture arp
Is there a VLAN on this network?
If so, try