Wireshark mailing list archives

Re: Basic question about Wireshark


From: "Frank Walter" <francwalter () gmx net>
Date: Fri, 29 Jul 2011 08:37:52 +0200

Im Auftrag von news.gmane.com
Gesendet: Donnerstag, 28. Juli 2011 16:32
An: wireshark-users () wireshark org
Betreff: Re: [Wireshark-users] Basic question about Wireshark


"Guy Harris" <guy () alum mit edu> wrote in message
news:38B92006-8402-4943-BBD5-AE1768CCA211 () alum mit edu...

On Jul 27, 2011, at 12:13 AM, Frank Walter wrote:

Are you talking about capture filter?
Unfortunately the capture filter syntax is different from display filter
syntax.
The capture filter
 not ether dest ff:ff:ff:ff:ff:ff
should exclude broadcast packets.

Oh no. This gives me a clear:

Invalid capture filter: "not ether dest ff:ff:ff:ff:ff:ff"!

The person who said "ether dest" was wrong - it should be "ether dst":

Sorry, I wrote the line from memory. But you're right, definitly.

Please,
where can I find a list of Capture Filter (to reduce the amount of packets to be captured) arguments for 802.11 Frames?
Would this Capture Filter work:
port 80 and port 8080 and port 443
?




___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: