Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Can't Capture EAPOL Packets Directly on Windows Device

Hi all,

I've been reading through a few other threads related to issues capturing EAPOL traffic but most of them seem to be people trying to capture traffic from a 3rd device monitoring between client and Wi-Fi controller/AP.

In my case, I have a Surface Pro running Windows and Wireshark and I'm just trying to capture EAPOL traffic between the Surface device and the Wi-Fi infrastructure.

I can capture Wi-Fi packets when connected to my home Wi-Fi WPA2 but when I attempt to connect to my work's Wi-Fi which uses Cisco ISE and EAP, the only thing I see is some SSDP packets on the loopback adapter.

Am I totally missing something here? Is this a hardware limitation with the Surface Wi-Fi adapter? I've tried promiscuous mode on and off. The adapter doesn't support monitor mode, but would that be relevant here since I'm running Wireshark on the device I'm trying to capture?

I've ordered a USB adapter that supports monitor mode but I'm not sure that is really the issue. Any help appreciated.

thanks, Dan