When Wireshark is installed in Windows 7's XP mode virtual machine, is it possible for Wireshark/WinPcap to put the network card into promiscuous mode? From some testing I have done, I don't think it can, as I can only capture traffic to or from my PC. If it is connected to destination port of a span session on a Cisco switch it cannot see traffic from the source port of the span.
If Wireshark is running directly under Windows 7, obviously all works well. If you are wondering why I am trying to use XP mode for this, it is just something I am testing out for work.
Thanks.