Wireshark-users: Re: [Wireshark-users] Having problem tracing multiple ip addresses

Date: Mon, 26 Apr 2021 07:23:43 +0000
Bob,

My first guess would be that you never see the packets on the interface you are snooping on. Can you check by removing the filter and see if you get them unfilterered?
Let's make sure we look at solving the right problem.

Regards, Hugo.

-----Original Message-----
From: Wireshark-users <wireshark-users-bounces@xxxxxxxxxxxxx> On Behalf Of Robert Blair
Sent: Friday, 23 April 2021 20:36
To: wireshaer <wireshark-users@xxxxxxxxxxxxx>
Subject: [Wireshark-users] Having problem tracing multiple ip addresses

I changed three IoT devices from DHCP to static addresses so I could trace all three of them.

when I enter "net 192.168.60.201" in the capture filter I get all traffic to and from the ip.

If I enter "net 192.168.60.200/30" I get all fraffic from the ip addresses but none going to the ip addresses.  According to the documentation at <https://wiki.wireshark.org/CaptureFilters> that syntax shoud capture all traffic going to and from the device.

Any assistance on getting the trace to work will be appreciated.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe