Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Wireshark does not need an IP address to capture traffic as it is just listening to the selected NIC interface. The reason why I am saying this is when you use a port mirror on a switch the interface will be active but you cannot seize an IP address from the DHCP server, as a port mirror is just one way traffic to the Wirehark PC. The same applies when you are using a TAP which allows for inline capturing of traffic