When capturing wireless 802.11 packets in Wireshark, is there a way to apply capture filters such as filtering specific SSID's? The NIC is operating in monitor mode so it is capturing broadcast packets from other SSIDs that i do not want.
Any help would be much appreciated.
Wireshark version 1.2.11 Ubuntu 10.10
asked 08 Feb '11, 14:02
Although not really regarding capture filters in wireshark, maybe this helps:
For generating the tracefiles I would recommend using airodumg-ng from the aircrack suite, especially when already running a linux OS.
Sample command for filtering specific SSID would be:
e.g. airodumg-ng -c 6 --bssid 00:13:29:11:22:33 -w /usr/sniffer/wireless-trace.pcap
Another advantage is, that airodump only captures one beacon frame per AP, thereby keeping trace fil size and readability much better
answered 10 Feb '11, 02:26
Thanks Landi for your reply.
One issue that i am getting is that when i run the above script; i am not getting the transmitted traffic. The test was performed on two machines connected via a ad-hoc connection and they were constantly pinging each other during the airmon-ng capture. However, when i run the tracefile in Wireshark, it does not show the ICMP (ping) packets, it shows the IEEE traffic which is what i want but i also need to see those ICMP packets too. Any ideas??
Really appreciate all your help.
answered 11 Feb '11, 05:08
filter: wlan.bssid eq mac_address_of_access_point
answered 16 Feb '11, 08:43