Ask Your Question

I need to setup a mac address filter to capture traffic from different devices.

asked 2019-05-27 11:51:11 +0000

AceSchia gravatar image

updated 2019-05-27 12:20:45 +0000

grahamb gravatar image

If I create such a filter ether host 9c:75:14:00:47:3c and ether host 9c:75:14:00:48:74, Wireshark replies "expression rejects all packets". How can I fix this ? Thanks in advance, Kind regards, Andrea

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2019-05-27 12:03:30 +0000

AceSchia gravatar image

updated 2019-05-27 12:14:49 +0000

grahamb gravatar image

Okay! Based on a post of Jim Aragon I understood I was misusing and instead of or. Now I setup (ether host 9c:75:14:00:47:3c) or (ether host 9c:75:14:00:48:74) and It's working ;-) Thank you Jim. Kind regards to everyone. Andrea

edit flag offensive delete link more


I'm glad that a posting of mine helped, but--there's nothing wrong with the capture filter in your question. It's valid capture filter syntax and it doesn't generate the "expession rejects all packets" message." Could it be that your original filter had "ether src host" in both terms, instead of "ether host"? Or "ether dst host"?

Jim Aragon gravatar imageJim Aragon ( 2019-05-27 17:27:19 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2019-05-27 11:51:11 +0000

Seen: 1,593 times

Last updated: May 27 '19