I'm having a problem with a capture filter. When I capture a host IP (host a.b.c.d) on a vlan with NO GRE tunnel the capture works perfect (I've done it hundres of times). When I move the capture vlan (change the VLAN that it is connected to on the Cisco switch - no physicl cable move just change the monitor port from vlan 500 to vlan 700) the capture stops capturing on a GRE tunnel VLAN. I've downloaded the latest version (3/22/12) with the same results. I know this has worked in the past 6 to 9 months ago. The only way I can get it to capture is to capture everything and then display filter for what I want. The display filture can then display down into the gre part of the package where it appears that the capture filture will not. I really need to only capture 1 IP to keep the size down low.
asked 23 Mar '12, 17:06
Assuming your host a.b.c.d is 192.168.1.100, then to capture all traffic to/from that GRE-encapsulated IP address, try* a capture filter of
If you want a capture filter that works* whether the IP address is GRE-encapsulated or not, then use
*NOTE: The filter, as is, only works as long as the IP header is 20 bytes in length and the GRE header is 8 bytes in length. If your IP or GRE headers differ in length, then the offsets of 40 and 44 will need to be adjusted accordingly.
answered 23 Mar '12, 19:16
edited 23 Mar '12, 20:14