Wireshark-users: Re: [Wireshark-users] Problem sniffing - getting only broadcasts (and it's not w
From: Sake Blok <sake@xxxxxxxxxx>
Date: Mon, 19 Nov 2007 22:10:30 +0100
On Mon, Nov 19, 2007 at 11:49:26AM -0600, Brian Swan wrote:
>  
> I've had a problem for a while now with my laptop and wireshark/WinPCap.  
> If I configure a mirror port on a switch, and sniff the traffic, all I 
> ever get is broadcasts (under windows).  

Is the "Capture packets in promiscuous mode" checkbox checked when you open
the Capture Options dialog? If it's not, the NIC will only forward unicasts
that were addressed to the NIC in your machine and multicast/broadcast 
frames to WinPcap.

Hope this helps,  Cheers,


Sake