Hi, I have Wireshark monitoring a TAP-Win32 Adapter connection installed with Cyberghost but the traffic doesn't show up as encrypted. Is this normal? And how do I check if traffic is encrypted through VPN. This happens with ProXPN also.

Many thanks

asked 12 Dec '10, 23:55

fh67's gravatar image

fh67
1111
accept rate: 0%


Yes, that is normal. If you capture on a virtual adapter that is used for a VPN connection you will see unencrypted packets in and out. The encryption happens when the virtual TAP adapter passes the data over to your physical network card. To see the encrypted traffic you need to capture on your "real" network card (wired or wireless) and you should see lots of encrypted packets.

In fact you can go and capture both with two Wireshark instances at the same time and then see how the unencrypted packets on the TAP adapter correlate to the physical adapter.

link

answered 13 Dec '10, 05:30

Jasper's gravatar image

Jasper ♦
14.9k338201
accept rate: 16%

edited 13 Dec '10, 05:31

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×23
×23

Asked: 12 Dec '10, 23:55

Seen: 8,868 times

Last updated: 13 Dec '10, 05:31

powered by OSQA