Ben Kevan wrote:
On Friday 18 July 2008 11:22:07 am James Knott wrote:
I often use Wireshark and it appears that with the version included with 11.0, the filters no longer work properly. For example, I currently have my notebook computer plugged into a "mirror" port on a switch, which will allow me to monitor traffic to and from another switch port. If I don't use filters, I can see all the traffic for that other port. However, if I use a capture filer, as simple as "ip", which should only display IP traffic, I only see traffic to or from my computer, including broadcasts & multicast. I do not see any unicast traffic for the monitored system.
Any ideas?
tnx jk
-- Use OpenOffice.org http://www.openoffice.org
What mode are you in on wireshark? Anything other than Promiscuous?
Promiscuous only. The only difference is when I don't use filters I see everything, but with any filter I don't see much. One reason I want to filter on IP only, is to eliminate all those spanning tree broadcasts. I've also tried filtering on host address and have the same problem. -- Use OpenOffice.org http://www.openoffice.org -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org For additional commands, e-mail: opensuse+help@opensuse.org