Wireshark-users: [Wireshark-users] Wireshark

From: RayMitchell <RayMitchell@xxxxxxxxxxxxxxxxxx>
Date: Fri, 07 Mar 2008 01:10:54 -0800
Hello,

I just installed Wireshark on WinXP and I have a question. I have Internet access through a cable modem and, thus, I have a LAN IP address (192.168.1.102) as well as an Internet DHCP IP address. I have a mail server running on my machine that is only visible to the LAN. The various email clients on my machine (Eudora, Outlook, etc.) seem to work fine using the LAN mail server for local email to each other as well as the mail server supplied by my ISP for Internet email. When I run Wireshark I can see all the email and other activity between my LAN machine and the Internet but absolutely no activity between my LAN mail server and any of the LAN mail clients, even though they all send and receive LAN-only messages fine. I've made sure that there are no filters turned on in Wireshark (at least I don't see any). It seems like for LAN-only activity Wireshark should be finding all kinds of packets where both the source and destination addresses are the same, namely the LAN IP address, but it only seems to find packets where one of the addresses is the LAN address and the other is an Internet address. Since I don't know much about the details of this stuff I'm probably missing something simple. Any ideas would be appreciated.

Thanks,
Ray Mitchell