Ask Your Question

Can I set up Wireshark to capture on a virtual IP configured on the local loopback subnet (i.e.

asked 2018-11-20 19:11:12 +0000

Yonaguska gravatar image

I have configured a set of virtual IPs on the local loopback subnet (i.e.>6) of my CentOS 6.10 VM. This is necessary to support testing in an environment where I can't simply add conventional VIPs to the NIC. I am trying to figure out how to configure Wireshark to capture traffic on one of these loopback VIPs, lo:1 (aka I see LO in the interface list, but none of the others.

lo:1 Link encap:Local Loopback inet addr: Mask: UP LOOPBACK RUNNING MTU:65536 Metric:1

Any ideas? There's no trace of my traffic on lo (, as expected.

Kind regards, -Kirk

edit retag flag offensive close merge delete

2 Answers

Sort by ยป oldest newest most voted

answered 2018-11-21 07:55:56 +0000

Jaap gravatar image

The 'others' are aliases of the loopback interface lo, where alias means 'other name for same thing'. In this case the same thing is the interface lo. So what you do is capture on lo and see the traffic for the aliases ( ...) as well as the main address ( It will all be on the same device, and that is what you capture on, not on an address.

edit flag offensive delete link more

answered 2018-11-20 22:55:46 +0000

npcap is supposed to support that. just wrote an article on it

edit flag offensive delete link more


I appreciate your quick reply, but I don't think I can use npcap. It appears to be a Windows driver, and I'm running on CentOS. But this suggests I might need to look at Libpcap's capabilities. Again, thanks for your help.

Yonaguska gravatar imageYonaguska ( 2018-11-20 23:08:07 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-11-20 19:11:12 +0000

Seen: 587 times

Last updated: Nov 21 '18