Wireshark mailing list archives

Re: Can't see http packets


From: Martin Visser <martinvisser99 () gmail com>
Date: Sat, 13 Mar 2010 21:35:16 +1100

My guess is that if you are only seeing NBNS,      DHCP,      ARP,     IGMP
protocol packets you are only seeing broadcasts from the rest of the
network.

You might need to really check that your port mirroring is working
correctly.

Regards, Martin

MartinVisser99 () gmail com


On Sat, Mar 13, 2010 at 2:03 AM, Ronan SAVY <R.SAVY () reponse fr> wrote:

 Hi

I would like to grab the http packet in order to have a clear view of web
usage before configuring some kind of filter over my compagnie network.

Here is what I installed:

I have a Windows XP SP3 workstation with wireshark installed on it and 2
nic one is a nvidia nforce and the other a D-link DFE-530TX

I connected the D-link NIC on port 16 of my 3com 2226-SFP Plus

Behind my 3 com switch I have 5 3com baseline switches connected in cascade

On port 25 of my switch I have a Linksys BEFSX41 with on his wan my FAI
modem going out on internet



I configured a port mirroring on port 16 from port 25 (I tried mirror in
solo, mirror out solo, and both)

I checked that the D-link nick can work on promiscuous mode (using promqry)



When I launch wireshark from station I can’t see any http traffic going out
safe from SSDP protocol

I also see other packet grab from other machine on my network, packet like
:

-          NBNS

-          DHCP

-          ARP

-          IGMP



Even when I browse internet on the workstation where wireshark is installed
using the second NIC… I can’t see the HTTP request going through



May be I did something wrong but I don’t know what? I checked the advanced
option of my NIC to see if there is Checksum offload option.. but nothing.



Any help would be most welcome as I have no more idea on what else I can
do.

thanks

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request () wireshark org
?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: