Nombre de usuario: 
Contraseña: 
Vincular sesión a esta IP 

Wireshark with mixed devices WIFI + WIRED

Clasificación global: 186
Puntuación total: 110531
Mensajes: 88
Agradecer: 78
Voto positivo: 91
Registrado: 9A 274d
Ávatar de occasus



Última vez visto: 13d 14m
El usuario está desconectado
Wireshark with mixed devices WIFI + WIRED
Google/Traductor1¡Gracias!1Buen mensaje!0Mal mensaje! link
Hi Altogether, hello Community,
I'm having a little issue with wireshark. Read for a few weeks official documentation and obviously uncle Google's results in order to find out where my problem could be. Sure fact is, that I'm overlooking something, but am not able to understand/solve the following issue.

On my private Linux laptop I connect through wifi into a classical LAN (192.168.120.0/24) with SSID "office".

Letting wireshark run on the wifi-interface in promiscuous mode the laptop pings to 192.168.120.164 (which is a charging station for electric cars connected to a switch), which answers and wireshark shows the ICMP requests and responses.

But if I give wireshark the filter
GeSHi`ed Plaintext código
1
ip.addr == 192.168.120.164
even for 24 hours, wireshark does not show anything. But I know for sure that the charging station (192.168.120.164) communicates quite constantly through internet/web...

As already stated in the beginning, I searched quite a while and applied many different display/capturing filters and read lots of documentation. But everything was to no avail...

Anyone have some suggestions? Thank you very much in advance Smile
Sincerely Yours
Clasificación global: 928
Puntuación total: 27562
Mensajes: 27
Agradecer: 18
Voto positivo: 22
Registrado: 10A 10h
Ávatar de Ketza
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor1¡Gracias!1Buen mensaje!0Mal mensaje! link
Hi,
- Try to just filter "icmp" and you'll maybe know what's wrong ?
- Maybe ipv6 related
- Maye some default filter applied
Clasificación global: 186
Puntuación total: 110531
Mensajes: 88
Agradecer: 78
Voto positivo: 91
Registrado: 9A 274d
Ávatar de occasus



Última vez visto: 13d 14m
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor1¡Gracias!1Buen mensaje!0Mal mensaje! link
Hi Ketza, thank you for replying. Unluckily I don't see where your 3 points help. Of course tried simple (dns, icmp, etc.) and letting them run for hours. Instead when applying no display filters... I see communication from many different ip addresses, but not the charging station...
3ports_chargestation.png
Clasificación global: 13942
Puntuación total: 142
Mensajes: 1
Agradecer: 1
Voto positivo: 1
Registrado: 348d 9h
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor1¡Gracias!1Buen mensaje!0Mal mensaje! link
Hi everyone! Maybe you somehow excluding that address? Haven't used Wireshark for some time and therefore do not remember in detail how I used it, maybe try add protocol and / or port? Maybe direction e.g. destination, source. Regards
Clasificación global: 3
Puntuación total: 675845
Mensajes: 70
Agradecer: 63
Voto positivo: 61
Registrado: 10A 99d
Ávatar de jusb3








Última vez visto: 10h 22m
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor2¡Gracias!3Buen mensaje!0Mal mensaje! link
Are you sure everything is working in promiscuous mode? I think the problem might be that packets between station and the router are not captured. You of course see the packets that are sent from laptop to station and from station to laptop, but not necessary packets between the router and station. If your router supports tcpdump, you could collect the packet capture of station IP on the router and analyze it on your laptop.
Clasificación global: 3
Puntuación total: 675845
Mensajes: 70
Agradecer: 63
Voto positivo: 61
Registrado: 10A 99d
Ávatar de jusb3








Última vez visto: 10h 22m
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor2¡Gracias!2Buen mensaje!0Mal mensaje! link
Cita de jusb3
Julio 03, 2023 - 13:44:38

Are you sure everything is working in promiscuous mode? I think the problem might be that packets between station and the router are not captured. You of course see the packets that are sent from laptop to station and from station to laptop, but not necessary packets between the router and station. If your router supports tcpdump, you could collect the packet capture of station IP on the router and analyze it on your laptop.

This faq question might be helpful:
https://www.wireshark.org/faq.html#promiscsniff
Clasificación global: 186
Puntuación total: 110531
Mensajes: 88
Agradecer: 78
Voto positivo: 91
Registrado: 9A 274d
Ávatar de occasus



Última vez visto: 13d 14m
El usuario está desconectado
RE: Wireshark with mixed devices WIFI + WIRED
Google/Traductor1¡Gracias!1Buen mensaje!0Mal mensaje! link
@jusb3 thank you for your time and making me wiser Smile carefully read that chapter of the faq more then once. Yep, maybe there is also vlan issues (now that I'm pondering), the laptop is connected to ssid office in the same vlan. But of course this is through wifi. The CS (charging station) is connected / wired to the switch. I will try to plug the eth-cable of the CS directly to the laptop and see if something happens...
tunelko, overthewire, ysx_hacking, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, kalungmas se suscribieron a este tema y reciben emails en nuevas publicaciones.
1 personas están viendo el tema ahora mismo.
Este tema ha sido visto 1613 veces.