Wireshark mailing list archives

Re: Wireshark V1.8.0 - analysing dual NIC capture


From: Guy Harris <guy () alum mit edu>
Date: Tue, 26 Jun 2012 14:25:55 -0700


On Jun 26, 2012, at 1:56 PM, Jeff Morriss wrote:

Pretty much, yes.  The intent (I think) was just to allow capturing on
2 interfaces simultaneously (rather than having to run 2
Wiresharks/dumpcaps and then merge the traces offline).

But nothing was added to separate out potentially-duplicated traffic.
(The use case is more for multi-homed hosts.)

Yes.  Not all ways you can perform multi-interface capture are necessarily *useful*.  Think of it as being similar to 
the "any" device on Linux (the differences are that

        1) you can control options on individual interfaces separately;

        2) the interfaces can supply different link-layer header types;

        3) you have to specify the list of interfaces when you start the capture).
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: