Wireshark-bugs: [Wireshark-bugs] [Bug 2747] Unable to capture from other switches in stack
Date: Thu, 31 Jul 2008 12:21:35 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2747





--- Comment #4 from Wglastonio <wglastonio@xxxxxxxxx>  2008-07-31 12:21:34 PDT ---
Hi Mr Keuter,

Follow some answers for your questions.

1) Do you run Windows XP on the same platform as Mandriva Linux?
[wg]yes.

2) What kind of platform do you capture on (hardware, NIC, etc)?
[wg]I made tests using a Dell notebook, model D531. In this notebook I have a
dual boot. I made tests using another PC, Pentium D based, motherboard Intel
with 2GBytes of RAM. For this second option only using Linux Mandriva.

3) Do you dual boot or run in a VMWare session?
[wg]On the notebook yes. I use dual boot.

4) How does the mirroring take place? Is it tagged traffic from the switch?
[wg]I don't if I understood this question. However, follow the information from
switch:

++++++++ CONFIG 1 ++++++++

<5500-EI>dis mirroring-group 1
mirroring-group 1:
    type: local
    status: active
    mirroring port:
        Ethernet1/0/16  both
     monitor port: GigabitEthernet1/0/50
<5500-EI>

++++++++ CONFIG 2 ++++++++

<5500-EI>dis mirroring-group 1
mirroring-group 1:
    type: local
    status: active
    mirroring port:
        Ethernet2/0/16  both
     monitor port: GigabitEthernet1/0/50
<5500-EI>

++++++++

If I use "Capture Filter" on the Wireshark (dumpcap, tshark), for the CONFIG 1,
is possible the capture. For the CONFIG 2, I can't capture any package.

I am interest in SIP packages, so I am using this "Capture Filter": port 5060


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.