why cant I see both sides of a SSDP M-SEARCH interaction?

asked 2018-01-02

ianc

updated 2018-01-02

I'm trying to understand the interaction between an SSDP M-Search initiator (Amazon Echo) and an ESP8266 based device emulating a Wemo switch.

I can see the the initiation message from the Echo in the WireShark packet log but not the response from the device although I am certain it is sent because the Echo acts on the response.

I know the IP and mac addr of both the devices.

I should say that this is the first time I've used WireShark.

What am I doing wrong?

How and where are you making the capture?

grahamb ( 2018-01-03 )

Hi Graham, I'm using a PC running WireShark (@ on the same private subnet as both devices (.32 and .72) Devices are Wifi connected, PC is wired. All on same router.

Standard out of the box set-up for WireShark - I just then filtered the network traffic on the IPs.

ianc ( 2018-01-03 )

answered 2018-01-03

grahamb

As you're not capturing on the router\AP, but on a PC connected to the router (which is in all likelihood a switch), then you'll only see broadcasts from the devices.

You can confirm this by looking at the initiation message and checking the destination IP.

To capture the non-broadcast traffic you'll need to either capture on the router, or over the air (which is problematic if using Windows for wireless capture).

Thanks Graham

ianc ( 2018-01-03 )

