Username: 
Password: 
Restrict session to IP 

Wireshark with mixed devices WIFI + WIRED

Global Rank: 180
Totalscore: 111481
Posts: 95
Thanks: 84
UpVotes: 98
Registered: 10y 79d
occasus`s Avatar



Last Seen: 2d 13h
The User is Offline
Wireshark with mixed devices WIFI + WIRED
Google/translate1Thank You!1Good Post!0Bad Post! link
Hi Altogether, hello Community,
I'm having a little issue with wireshark. Read for a few weeks official documentation and obviously uncle Google's results in order to find out where my problem could be. Sure fact is, that I'm overlooking something, but am not able to understand/solve the following issue.

On my private Linux laptop I connect through wifi into a classical LAN (192.168.120.0/24) with SSID "office".

Letting wireshark run on the wifi-interface in promiscuous mode the laptop pings to 192.168.120.164 (which is a charging station for electric cars connected to a switch), which answers and wireshark shows the ICMP requests and responses.

But if I give wireshark the filter
GeSHi`ed Plaintext code
1
ip.addr == 192.168.120.164
even for 24 hours, wireshark does not show anything. But I know for sure that the charging station (192.168.120.164) communicates quite constantly through internet/web...

As already stated in the beginning, I searched quite a while and applied many different display/capturing filters and read lots of documentation. But everything was to no avail...

Anyone have some suggestions? Thank you very much in advance Smile
Sincerely Yours
Global Rank: 913
Totalscore: 28652
Posts: 35
Thanks: 25
UpVotes: 29
Registered: 10y 170d
Ketza`s Avatar
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate1Thank You!1Good Post!0Bad Post! link
Hi,
- Try to just filter "icmp" and you'll maybe know what's wrong ?
- Maybe ipv6 related
- Maye some default filter applied
Global Rank: 180
Totalscore: 111481
Posts: 95
Thanks: 84
UpVotes: 98
Registered: 10y 79d
occasus`s Avatar



Last Seen: 2d 13h
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate1Thank You!1Good Post!0Bad Post! link
Hi Ketza, thank you for replying. Unluckily I don't see where your 3 points help. Of course tried simple (dns, icmp, etc.) and letting them run for hours. Instead when applying no display filters... I see communication from many different ip addresses, but not the charging station...
3ports_chargestation.png
Global Rank: 14141
Totalscore: 147
Posts: 1
Thanks: 1
UpVotes: 1
Registered: 1y 153d
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate1Thank You!1Good Post!0Bad Post! link
Hi everyone! Maybe you somehow excluding that address? Haven't used Wireshark for some time and therefore do not remember in detail how I used it, maybe try add protocol and / or port? Maybe direction e.g. destination, source. Regards
Global Rank: 3
Totalscore: 679397
Posts: 71
Thanks: 65
UpVotes: 64
Registered: 10y 269d
jusb3`s Avatar








Last Seen: 3d 19h
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate2Thank You!3Good Post!0Bad Post! link
Are you sure everything is working in promiscuous mode? I think the problem might be that packets between station and the router are not captured. You of course see the packets that are sent from laptop to station and from station to laptop, but not necessary packets between the router and station. If your router supports tcpdump, you could collect the packet capture of station IP on the router and analyze it on your laptop.
Global Rank: 3
Totalscore: 679397
Posts: 71
Thanks: 65
UpVotes: 64
Registered: 10y 269d
jusb3`s Avatar








Last Seen: 3d 19h
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate2Thank You!2Good Post!0Bad Post! link
Quote from jusb3
Jul 03, 2023 - 13:44:38

Are you sure everything is working in promiscuous mode? I think the problem might be that packets between station and the router are not captured. You of course see the packets that are sent from laptop to station and from station to laptop, but not necessary packets between the router and station. If your router supports tcpdump, you could collect the packet capture of station IP on the router and analyze it on your laptop.

This faq question might be helpful:
https://www.wireshark.org/faq.html#promiscsniff
Global Rank: 180
Totalscore: 111481
Posts: 95
Thanks: 84
UpVotes: 98
Registered: 10y 79d
occasus`s Avatar



Last Seen: 2d 13h
The User is Offline
RE: Wireshark with mixed devices WIFI + WIRED
Google/translate1Thank You!1Good Post!0Bad Post! link
@jusb3 thank you for your time and making me wiser Smile carefully read that chapter of the faq more then once. Yep, maybe there is also vlan issues (now that I'm pondering), the laptop is connected to ssid office in the same vlan. But of course this is through wifi. The CS (charging station) is connected / wired to the switch. I will try to plug the eth-cable of the CS directly to the laptop and see if something happens...
tunelko, overthewire, ysx_hacking, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, csuquvq have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 1867 times.