[Winpcap-users] WinPcap 4 & Cisco Spanned Ports

Bryan Kadzban bryan at kadzban.is-a-geek.net
Fri May 11 17:03:03 GMT 2007

On Fri, May 11, 2007 at 02:24:36PM +0100, Keith French wrote:
> I am using Tshark supplied with Wireshark V0.10.5 and trying to use a
> capture filter when a monitoring a Cisco Catalyst 2950 span port.

Is the machine's NIC in promiscuous mode?  We've had issues with that
before (though with 3com switches).

> I am trying to span a trunk port and look at 802.1Q VLAN headers, but
> if I specify a valid capture filter of host no packets
> are captured.

Oh, never mind, this has nothing to do with promiscuous mode.

The bottom of http://wiki.ethereal.com/CaptureSetup/VLAN says that "any
capture filter that is to be applied to packets with 802.1q tags has to
have "vlan and" at the beginning".  :-)

(But I cheated when finding this: I figured the issue was that WinPcap
didn't use the right frame offsets if it got a tagged frame from the
hardware driver.  So I went looking for the VLAN-specific setup page
that I remembered reading before when doing something similar myself,
and found the URL above.)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://www.winpcap.org/pipermail/winpcap-users/attachments/20070511/55b86748/attachment.pgp

More information about the Winpcap-users mailing list