Ask Your Question

JohnBoy's profile - activity

2021-06-27 02:53:43 +0000 received badge  Popular Question (source)
2021-06-25 08:29:16 +0000 received badge  Famous Question (source)
2020-09-21 18:00:57 +0000 commented question tshark or dumpcap affecting RDP session on Windows Server 2012R2

I think the problem is related to processor affinity. I have observed when dumpcap runs, CPU 0 and 1 in my 12 core syst

2020-09-21 15:38:55 +0000 commented question tshark or dumpcap affecting RDP session on Windows Server 2012R2

I have tried 3.26 and 3.30 with ncpap 0.9997 to no avail. As long as tshark or dumcap is running, RDP sessions to the se

2020-09-16 14:37:42 +0000 commented question tshark or dumpcap affecting RDP session on Windows Server 2012R2

Thanks guys... I'll give the new version a go and see how I make out. Cheers.

2020-09-16 11:53:07 +0000 commented question tshark or dumpcap affecting RDP session on Windows Server 2012R2

Thanks for your response. Here is the output of that command: TShark (Wireshark) 3.2.4 (v3.2.4-0-g893b5a5e1e3e) Copyr

2020-09-15 19:55:07 +0000 asked a question tshark or dumpcap affecting RDP session on Windows Server 2012R2

tshark or dumpcap affecting RDP session on Windows Server 2012R2 Has anyone encountered RDP performance issues while run

2020-09-12 16:01:41 +0000 received badge  Notable Question (source)
2020-07-24 21:57:34 +0000 received badge  Popular Question (source)
2019-06-21 16:22:39 +0000 marked best answer dumpcap problem with multiple interfaces and filter

I am running Wireshark 64 bit v3.0.2 under Windows Server 2012 R2.

I believe I have run into a bug with dumpcap specifically.

My dumpcap cmd line looks like this:

dumpcap -i 3 -i 9 -f "host 172.20.1.2" -b filesize:50000 -b files:20  -w "D:\captures\172-20-1-2.pcapng"

Interfaces 3 and 9 are SPAN ports from my two Nexus 7000 core switches.

When I run this cmd as is, the filter DOES NOT work. All packets on the wires are captured. If I run this same cmd specifying only one interface (either of them), the filter works properly.

Is this a bug or a limitation of some kind?

If I were to run two separate dumpcap instances (in their own cmd shell), can I merge the two pcapng files later into one, preserving the packet order?

Thanks in advance.

John

2019-06-21 16:22:39 +0000 received badge  Scholar (source)
2019-06-21 16:22:29 +0000 commented answer dumpcap problem with multiple interfaces and filter

Thanks very much Graham... your suggestion worked!! Egg on my face. I actually did read the man page but not closely e

2019-06-21 16:02:06 +0000 received badge  Editor (source)
2019-06-21 16:02:06 +0000 edited question dumpcap problem with multiple interfaces and filter

dumpcap problem with multiple interfaces and filter I am running Wireshark 64 bit v3.0.2 under Windows Server 2012 R2.

2019-06-21 15:51:59 +0000 asked a question dumpcap problem with multiple interfaces and filter

dumpcap problem with multiple interfaces and filter I am running Wireshark 64 bit v3.0.2 under Windows Server 2012 R2.