Wireshark-users: Re: [Wireshark-users] Capture Filter not work for hub, seems like a bug?
From: Sake Blok <sake@xxxxxxxxxx>
Date: Wed, 26 Aug 2009 21:04:05 +0200
On Wed, Aug 26, 2009 at 09:42:08AM -0700, Gerald Combs wrote:
> Tao Zhou wrote:
> > 
> > But today I found that the laptop NIC card has not obtained a valid IP
> > address, as it uses DHCP; while STB got an public network IP address
> > through PPPoE.
> 
> Are you trying to apply a capture filter to PPPoE traffic? If so, you
> might want to try something like "pppoes && port 80". According to the
> tcpdump man page you need to use it in order for your filter to use the
> proper offsets.

And if that does not work, you might want to post a binary capture of
the http traffic (when no capture filter is used) so that we can have a
look why the filter "port 80" might not have worked...

> > So I guess maybe the root cause is that without an IP address for
> > laptop, the 'Capture Filter' will make it could not capture any packets;
> > while leaving it empty will get all packets in the hub successfully.

Nope, you don't need (and ofter even do not want) an IP address on the
capture interface.

Cheers,
    Sake