• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 303
  • Last Modified:

wireshar for IP ARP

I wish to apply a display filter to a Wireshark capture that contains several ARP exchanges when no filter is applied.
I have tried three different filters (one at a time) as follows:
 ip.proto == ARP
 ip.proto == 0x0806
 ip.proto == 2054
 but in either case, when the filter is applied there are no packets shown.

What filter should I be applying ?

I am using Version 1.6.5 (SVN Rev 40429 from /trunk-1.6)
0
alcindor
Asked:
alcindor
2 Solutions
 
Zephyr ICTCloud ArchitectCommented:
I thought it was just arp to filter arp ...

So to filter arp just put "arp" in the filter part. Or maybe "ether proto \arp "

Unless you're trying to really filter something specific??
0
 
giltjrCommented:
You can either just put ARP or eth.type == 0x0806

ARP is not an IP protocol it is a protocol "equal" to IP.
0
 
alcindorAuthor Commented:
Thanks guys
0

Featured Post

[Webinar] Kill tickets & tabs using PowerShell

Are you tired of cycling through the same browser tabs everyday to close the same repetitive tickets? In this webinar JumpCloud will show how you can leverage RESTful APIs to build your own PowerShell modules to kill tickets & tabs using the PowerShell command Invoke-RestMethod.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now