I need to setup a mac address filter to capture traffic from different devices.

asked 2019-05-27

AceSchia

updated 2019-05-27

grahamb

If I create such a filter ether host 9c:75:14:00:47:3c and ether host 9c:75:14:00:48:74, Wireshark replies "expression rejects all packets". How can I fix this ? Thanks in advance, Kind regards, Andrea

answered 2019-05-27

AceSchia

updated 2019-05-27

grahamb

Okay! Based on a post of Jim Aragon I understood I was misusing and instead of or. Now I setup (ether host 9c:75:14:00:47:3c) or (ether host 9c:75:14:00:48:74) and It's working ;-) Thank you Jim. Kind regards to everyone. Andrea

I'm glad that a posting of mine helped, but--there's nothing wrong with the capture filter in your question. It's valid capture filter syntax and it doesn't generate the "expession rejects all packets" message." Could it be that your original filter had "ether src host" in both terms, instead of "ether host"? Or "ether dst host"?

Jim Aragon ( 2019-05-27 )

Asked: 2019-05-27

Seen: 1,593 times

Last updated: May 27 '19