Wireshark-users: Re: [Wireshark-users] filtering on Ethernet MAC OUI
From: Wes <wes_r@xxxxxxxxx>
Date: Wed, 1 Apr 2009 14:46:34 -0700 (PDT)
Here is one way:

eth.addr contains 00:21:91

Wes

--- On Wed, 4/1/09, noah davids <ndav1@xxxxxxx> wrote:

> From: noah davids <ndav1@xxxxxxx>
> Subject: [Wireshark-users] filtering on Ethernet MAC OUI
> To: Wireshark-users@xxxxxxxxxxxxx
> Date: Wednesday, April 1, 2009, 7:27 AM
> 
> 
>  
>  
> 
> 
>  
> Is there any way to filter on just
> the Ethernet MAC OUI? 
> I've tried data [0:2] but that only does the data and
> there does not appear to 
> be a frame [0:2].
>  
>  
> Noah Davids
> =+=+=+=+=+=+=+=+=+=+=+=+=+=+
> Serendipity 
> is a function of bandwidth
>  
> 
> -----Inline Attachment Follows-----
> 
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>          
>    mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe