Hi Martin, Indeed Guy’s reply fits well. And I agree that human security control works well. But a human is a human (rather a greedy animal :-)
and curiosity spares none. When I initially posted this question I did not put forth my views/suggestions. Hence, the confusion. Sorry for that. Now it is clear as to what my call is for this issue. Thanks to all who replied to my topic and helped me decide how to solve this issue. Kind regards, Nag. From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of
Martin Visser Nag., On Wed, Jun 16, 2010 at 3:01 PM, Maynard, Chris <Christopher.Maynard@xxxxxxxxx> wrote: I was confused by the question too, but if I focus only on the question asked, namely, "Is
there a way to capture packets from/to a selected list of IP address on a LAN?", then the answer is yes.
First you must set things up so the machine doing the capturing has access to the packets of interest. This may involve adding a hub, enabling port
mirroring on a switch, etc. See
http://wiki.wireshark.org/CaptureSetup for more information. And second, you must use an appropriate capture filter. For example, if you want to capture all packets sent from/to 2 hosts (assume IP
addresses IP1 and IP2), to any other host then you might use the following capture filter to accomplish this: "host IP1 or host IP2". If you only want to see packets sent between those 2 hosts, then you would use, "host IP1 and host IP2". See
http://wiki.wireshark.org/CaptureFilters for more information on capture filters. Now if you want to "restrict
the packet capturing to a set of machines ...", then that's a different problem to solve. - Chris From:
wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx]
On Behalf Of Martin Visser Sent: Tuesday, June 15, 2010 8:57 PM
Nag, On Tue, Jun 15, 2010 at 6:55 PM, Nagendrababu Maseedu <Nagendra.Babu.Maseedu@xxxxxxxxxxxxx>
wrote: Hi,
Is there a way to capture packets from/to a selected list of IP address on a LAN?
The need is to restrict the packet capturing to a set of machines so that security breach does not happen on other machines on the same network.
Please let me know if you have any other mechanism to satisfy this need.
Kind regards,
Nag. NOTICE: The information contained in this electronic mail transmission is intended by Convergys Corporation for the use of the named individual
or entity to which it is directed and may contain information that is privileged or otherwise confidential. If you have received this electronic mail transmission in error, please delete it from your system without copying or forwarding it, and notify the
sender of the error by reply email or by telephone (collect), so that the sender's address records can be corrected.
CONFIDENTIALITY NOTICE: The contents of this email are confidential
and for the exclusive use of the intended recipient. If you receive this
email in error, please delete it from your system immediately and
notify us either by email, telephone or fax. You should not copy,
forward, or otherwise disclose the content of the email.
NOTICE: The information contained in this electronic mail transmission is intended by Convergys Corporation for the use of the named individual or entity to which it is directed and may contain information that is privileged or otherwise confidential. If you have received this electronic mail transmission in error, please delete it from your system without copying or forwarding it, and notify the sender of the error by reply email or by telephone (collect), so that the sender's address records can be corrected. |
- References:
- [Wireshark-users] Secured way of using Wireshark
- From: Nagendrababu Maseedu
- Re: [Wireshark-users] Secured way of using Wireshark
- From: Martin Visser
- Re: [Wireshark-users] Secured way of using Wireshark
- From: Maynard, Chris
- Re: [Wireshark-users] Secured way of using Wireshark
- From: Martin Visser
- [Wireshark-users] Secured way of using Wireshark
- Prev by Date: Re: [Wireshark-users] Saving packet related information in pinfo.private_data
- Next by Date: Re: [Wireshark-users] hi,can you give me some help about PPPoE packets?
- Previous by thread: Re: [Wireshark-users] Secured way of using Wireshark
- Next by thread: [Wireshark-users] UDP MP2T Jitter MDI DF MLR
- Index(es):