Wireshark-users: Re: [Wireshark-users] Capturing packets on dial-up connections
From: "Darren Mease" <Darren.Mease@xxxxxxxxxxxxxxxx>
Date: Wed, 22 Nov 2006 10:11:29 -0000
Hi Guy, That's great, cheers. Tested with Windump and got same results. I was running WinPCap 4.0 Alpha, and have gone to Beta2. All working now. Cheers for the help! -----Original Message----- From: Guy Harris [mailto:guy@xxxxxxxxxxxx] Sent: 21 November 2006 18:28 To: Community support list for Wireshark Subject: Re: [Wireshark-users] Capturing packets on dial-up connections Darren Mease wrote: > I am trying to capture packets when dialling up, and can select the > interface, that shows the correct IP and that it is capturing packets. > However, when looking at the packets, all I get is a long list of: > > > > Ethern [Packet size limited during capture] Ethernet? That means you're probably doing this on Windows. If so, try doing a capture with WinDump and with the "-s 0" flag (to ensure that WinPcap isn't deliberately limiting the packet size during capture) and the "-w" flag to write it in binary format to a file, and then try reading the file. ("windump -D" will list the interfaces, with names and numbers; the number given for an interface in the output of "windump -D" can be used as an argument to the "-i" flag to get WinDump to capture on that interface.) Then try reading that file with Wireshark; if you get the same problem, this is almost certainly a WinPcap issue - report it to the WinPcap developers: http://www.winpcap.org/bugs.htm In step 5, report, in addition to all that information, any special networking software you might be running (firewalls, VPN software, etc.). If you're not doing this on Windows, please tell us what version of what operating system you're using. _______________________________________________ Wireshark-users mailing list Wireshark-users@xxxxxxxxxxxxx http://www.wireshark.org/mailman/listinfo/wireshark-users -- Darren Mease Security Operations Engineer Boxing Orange Ltd t: 0871 871 2774 f: 0871 871 0068 Darren.Mease@xxxxxxxxxxxxxxxx http://www.boxingorange.com/ This message (and any associated files) is intended only for the use of the individual or entity to which it is addressed and may contain information that is confidential, subject to copyright or constitutes a trade secret. If you are not the intended recipient you are hereby notified that any dissemination, copying or distribution of this message, or files associated with this message, is strictly prohibited. If you have received this message in error, please notify us immediately by replying to the message and deleting it from your computer. Messages sent to and from us may be monitored. Internet communications cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, destroyed, arrive late or incomplete, or contain viruses. Therefore, we do not accept responsibility for any errors or omissions that are present in this message, or any attachment, that have arisen as a result of e-mail transmission. If verification is required, please request a hard-copy version. Any views or opinions presented are solely those of the author and do not necessarily represent those of the company.
- Prev by Date: [Wireshark-users] 2 gig limit on mergecap
- Next by Date: Re: [Wireshark-users] 2 gig limit on mergecap
- Previous by thread: Re: [Wireshark-users] Capturing packets on dial-up connections
- Next by thread: [Wireshark-users] HASH data output tshark
- Index(es):