Wireshark-users: Re: [Wireshark-users] Capture filter for ARP, DNS and PING

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Sun, 06 Jan 2008 19:45:11 -0800
nilay yildirim wrote:
Thanks. So how about if I wanted to only capture all packets to and from <> ( host ip adress) but just arp, dns and ping? What does this changes? Or I need to create another filter???

ARP packets don't go to or from IP addresses - they go to or from MAC addresses, so you can't capture ARP traffic to or from, as that notion makes no sense.

However, you could do

host and (port domain or icmp[icmptype] = icmp-echo or icmp[icmptype] = icmp-echoreply)

which will capture DNS and ICMP ping traffic to or from