Wireshark-users: Re: [Wireshark-users] View Filter -> Capture Filter

From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Wed, 25 Oct 2006 21:45:39 -0700
On Thu, Oct 26, 2006 at 02:33:19PM +1000, sallas@xxxxxxxxxx wrote:

> Anybody knows what the Capture Filter equivalent is of the following 
> View Filter: ldap.authentication == 0
> 
> I am basically trying to whittle down my capture to simple 
> authentication requests over LDAP (389) as part of an investigation 
> into using LDAPS.

Unfortunately, there is no way to get that much detail in a capture 
filter.  The best you can do is set the capture filter to only capture 
LDAP traffic with "tcp port 389".


Steve