Wireshark-users: Re: [Wireshark-users] Query on Teamed Interfaces
From: Martin Visser <martinvisser99@xxxxxxxxx>
Date: Tue, 20 Oct 2009 21:11:29 +1100
Charles,

I expect that it could well be that WinPcap does not operate correctly on teamed interfaces (at least under XP). Assuming that you have tried capturing on all of the available interfaces (as presented by Wireshark) then you are probably going to need to use a different strategy, which is to capture on the network. The best thing is to connect your workstation to a managed switch that supports "span ports" or port-mirroring. Then simply configure the switch to send a mirrored copy of your workstation,s interfaces to another port where you have a wireshark-equipped box capturing the traffic 

Regards, Martin

MartinVisser99@xxxxxxxxx


On Sat, Oct 17, 2009 at 7:15 AM, <Charles_Johnson@xxxxxxxxxxxxx> wrote:

Nick:

Thank you for getting back to me.

We are running Network Fault Tolerant mode.   In a team, neither port is carrying the IP address,  the IP resides within the Team itself.
We tried monitoring via the active NIC and basically had no packets captured.  Through the Team we are able to capture packets.
We are filtering on Port 80 and seeing minimal amounts of traffic.   We were expecting alot more traffic than what we are seeing.
The machine is an HP DL380 that has the Teaming feature.


Charles Johnson
Broadcast Network Engineer
MTP&O Engineering - DCTC
Discovery Communications
8045 Kennett Street
Silver Spring, MD 20910
Office # 240.662.4819
Cell # 301.633.4069



From: <NMaio@xxxxxxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Date: 10/16/2009 04:00 PM
Subject: Re: [Wireshark-users] Query on Teamed Interfaces
Sent by:
wireshark-users-bounces@xxxxxxxxxxxxx





Charles,
Have you tried to just select the active interface of the team if the team is in an active/standby configuration?
Nick
 
 
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Charles_Johnson@xxxxxxxxxxxxx
Sent:
Friday, October 16, 2009 3:53 PM
To:
wireshark-users@xxxxxxxxxxxxx
Subject:
[Wireshark-users] Query on Teamed Interfaces

 

We are running Wireshark on a Windows XP machine that has teamed interfaces (NICs) and are not capturing packets as we have on machines with non-teamed interfaces (NICs)


Has anyone run across an issue with teamed NICs?  Is there a workaround within Wireshark?


Thank you!


Charles Johnson
Broadcast Network Engineer
MTP&O Engineering - DCTC
Discovery Communications
8045 Kennett Street
Silver Spring, MD 20910
Office # 240.662.4819
Cell # 301.633.4069



The storms are bigger, the teams are faster and action has never been more explosive.  STORM CHASERS roars back Sunday, October 18 at 10 PM (EP/PT) for an all-new season on Discovery Channel.  Hold on for the ride of your life!


***********************************************************************************************************************************************
This e-mail, and any attachment, is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, re-transmission, copying, dissemination or other use of this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any computer. The contents of this message may contain personal views which are not the views of Discovery Communications, LLC.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    
http://www.wireshark.org/lists/wireshark-users
Unsubscribe:
https://wireshark.org/mailman/options/wireshark-users
           
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe




The storms are bigger, the teams are faster and action has never been more explosive.  STORM CHASERS roars back Sunday, October 18 at 10 PM (EP/PT) for an all-new season on Discovery Channel.  Hold on for the ride of your life!

***********************************************************************************************************************************************
This e-mail, and any attachment, is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, re-transmission, copying, dissemination or other use of this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any computer. The contents of this message may contain personal views which are not the views of Discovery Communications, LLC.

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe