Wireshark filtering syntax

trojan81
trojan81 used Ask the Experts™
on
HeLLo
I have a wireshark packet capture.  I wan to do these two things but cannot get the syntax correct:

1)  Filter out all broadcast traffic

2) Filter out any destination that is within the address range 10.0.0.0/8
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Top Expert 2015
Commented:
1) not possible, you can filter out your broadcast addresses similar to (2)
2) !ip.dst == 10.0.0.0/8
Commented:
Hi. When you say "filter out" I am assuming that is the specific traffic that you want to see. I think the above poster assumed the opposite.

1) not (eth.addr == ff:ff:ff:ff:ff:ff||eth.addr contains 01:00:5e)
2) ip.dst == 10.0.0.0/8

1&2) ip.dst == 10.0.0.0/8 and not (eth.addr == ff:ff:ff:ff:ff:ff||eth.addr contains 01:00:5e)
btanExec Consultant
Distinguished Expert 2018
Commented:
1. Looks like most go for multicast instead. E.g.
... (eth.dst[0] & 1) . Multicast traffic is recognized by the least significant bit of the most significant byte of the MAC address. If 1, multicast, if 0, not.
an very old sharing which you may read on ..
https://www.wireshark.org/lists/ethereal-users/200107/msg00170.html

2. Same as gheist

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial