| 1 | initial version |
Wireshark does not need an IP address to capture traffic as it is just listening to the selected NIC interface. The reason why I am saying this is when you use a port mirror on a switch the interface will be active but you cannot seize an IP address from the DHCP server, as a port mirror is just one way traffic to the Wirehark PC. The same applies when you are using a TAP which allows for inline capturing of traffic