How To Use Wireshark At Home
Use wireshark to capture and analyze ethernet frames.
How to use wireshark at home. You can also tell if the packet is part of a conversation. How to use wireshark on windows if you want to install wireshark on your windows machine look for the appropriate version to download. To begin capturing packets with wireshark. In the wireshark capture interfaces window select start. How to filter and inspect packets in wireshark you can apply wireshark filters in two ways.
Determine the ip address of the default gateway on your pc. Make sure you have selected the windows version of the. In the display filter window at the top of the screen by highlighting a packet or a portion of a packet and right clicking on the packet. To select multiple networks hold the shift key as you make your selection. When you start typing wireshark will help you autocomplete your filter.
Select one or more of networks go to the menu bar then select capture. The most basic way to apply a filter is by typing it into the filter box at the top of the window and clicking apply or pressing enter. We are selecting eth0 because our network interface is an ethernet connection. You will then examine the information that is contained in the frame header fields. Open a windows command prompt.
Most people use wireshark to detect problems in their network and troubleshoot based on that but developers for instance can use it to debug programs. When you click on a packet the other two panes change to show you the details about the selected packet. Network security engineers can examine security issues qa engineers verify network applications and the plain old tech savvy person can use wireshark to learn network protocol internals. Particularly if you are using linux wireshark must be available directly from your distribution s repositories for an easier install at your convenience. That s where wireshark s filters come in.
Now you will have to click on the start button. The packet list the top pane is a list of all the packets in the capture. For example type dns and you ll see only dns packets. Wireshark shows you three different panes for inspecting packet data.