Ask Your Question
0

Source, destination, protocol blank

asked 2020-12-12 09:32:15 +0000

EssexGeoff gravatar image

I'm successfully capturing TCP/IP traffic between PC (W10) and an external device. Capture filter uses IP address of device. Data looks OK but the columns source, destination and protocol are all blank.

edit retag flag offensive close merge delete

Comments

Did you slice the packets to only 34 bytes or less? What do you see? Can you share a pcap file? It's really hard to see from here what you are seeing ;-)

SYN-bit gravatar imageSYN-bit ( 2020-12-12 12:00:34 +0000 )edit

Thanks for the prompt response! I am new to to Wireshark, but hope this will help explain: https://www.dropbox.com/s/a6t9al1r4ul...

EssexGeoff gravatar imageEssexGeoff ( 2020-12-12 12:51:33 +0000 )edit

1 Answer

Sort by ยป oldest newest most voted
0

answered 2020-12-12 13:01:41 +0000

SYN-bit gravatar image

@EssexGeoff Thanks for the pcap file. There is nothing wrong with the file, as it is showing data in the source/destination/protocol columns. So it must be something in your wireshark settings.

You can delete your current preferences by opening the "About Wireshark" menu item (under Help on Win/Linux/*ux, or uder "Wireshark" on MacOS). Then go to the "Folder" tab and double-click on the entry that says "Personal Configuration". Once that folder is open, close Wireshark first and then delete all the files in the personal configuration folder (you can leave the plugins and profiles folders if you like).

Now reopen Wireshark and load the file again, the columns should now be populated...

edit flag offensive delete link more

Comments

Thank you, that looks much better! :-)

EssexGeoff gravatar imageEssexGeoff ( 2020-12-12 14:07:05 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2020-12-12 09:32:15 +0000

Seen: 1,500 times

Last updated: Dec 12 '20