Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

UDP Packets: visibility depends on IP address

I have a device that emits SYSLOG messages over a UDP address and port that I specify. If I specify an IP address inside my local router subnet, i.e., 192.168.50.xx (with a PC or Mac also inside, i.e., at another 192.168.50.yy), I can see the packets on WireShark.

If I change the device to specify an IP address outside my local router subnet (e.g., 52.2.xxx.yyy), they don't show up on Wireshark. However, I know they reach their destination (a SaaS logging service).

Note that I do see UDP packets from other devices in my home with Wireshark.

Note that the computers running Wireshare (PC, Mac) and device are all hardwired on same ethernet switch, which is connected to my home router through another switch. Firewall is off on both computers. All protocols are enabled in Wireshark. No other anti-virus software.