| 1 | initial version |
There is no way to do this on the server while booting as the Wireshark application can only run once the server is fully functional. The closest you will get to this, is to do a port mirror (port span) on the network interface to a seperate PC on which Wireshark runs all the time. You will then be able to capture the ARPs, broadcasts, DHCP, LLDP or CDP etc packets. This capture will unfortunately NOT show anything about the Windows boot process.