Re: [Wireshark-users] Understanding what I'm seeing

2007-10-11 Thread Chad Webb
EUREKA! I removed the Symantec Client VPN application, Wireshark and WinPcapreinstalled Wireshark and WinPcap and "I can see clearly now". I had looked through the Symantec Client VPN app before to turn off the internal firewall, but that didn't help. Maybe on install the application doe

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-11 Thread Chad Webb
Thanks for the response. The reason I don't think it is the switch configuration is because I'm seeing the same result on 4 different switches (3 different 3560Gs and one 3550). I don't handle the Windows patching/installation and I believe something has been added/patched on my laptop (wireshark

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-11 Thread Giles Coochey
> When http attempt is made to www.4thegame.com (213.160.120.1) all I see > is: > > SourceDestination ProtocolInfo > 127.0.0.1 213.160.120.1 ICMPEcho (ping) request > > There is definitely something wrong with your network. You should never, ever se

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Chad Webb
Bill, That's exactly what I've done. Without the system being a monitor, capturing packets while browsing the Internet displays packets as I expect. -Chad Bill Baltas said the following on 10/10/2007 1:30 PM: > Chad, > > Your capture ports look okay. Could you have a capture filter defined

[Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Bill Baltas
Chad, Your capture ports look okay. Could you have a capture filter defined in Wireshark? Also, are you sure the capture workstation is not working properly. One easy way to check the workstation is to turn off the capture to the destination port (no monitor session 1 destination interface Gi

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Chad Webb
Removed SPAN configuration and reconfigured net-gig2#conf t Enter configuration commands, one per line. End with CNTL/Z. net-gig2(config)#monitor session 1 source interface Gi0/21 net-gig2(config)#monitor session 1 destination interface Gi0/22 net-gig2(config)#^Z net-gig2# net-gig2#sh monitor

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Randy . Grein
rk" cc Subject Re: [Wireshark-users] Understanding what I'm seeing > > Obviously the port monitoring is incorrect. Cisco does a great job of > being inconsistent across their product line (but don't tell that to the > layer 3 guys - most insist Cisco can do no

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Rafael . Almeida
10/10/2007 10:20 Favor responder a Community support list for Wireshark Para wireshark-users@wireshark.org cc Assunto [Wireshark-users] Understanding what I'm seeing I'm currently using version 0.99.6 on a Windows platform. I have the following configuration set up on my Cisco 3560

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread juan.wortley
ommunity support list for Wireshark >Subject: Re: [Wireshark-users] Understanding what I'm seeing > >If your network card is known to work in "promiscuous mode" >the problem is probably that the mirror port is not working propperly. > >If CDP is enabled and you see

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Luis EG Ontanon
If your network card is known to work in "promiscuous mode" the problem is probably that the mirror port is not working propperly. If CDP is enabled and you see CDP packets whose source interface is declared to be the one you are connected, the mirroring is not working properly, it is working as a

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Sake Blok
To: "Community support list for Wireshark" Sent: Wednesday, October 10, 2007 6:08 PM Subject: Re: [Wireshark-users] Understanding what I'm seeing >I do have "promiscous mode" checked within the Options screen > > Luis EG Ontanon said the following on 10/10/2007 10:22 A

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Chad Webb
I do have "promiscous mode" checked within the Options screen Luis EG Ontanon said the following on 10/10/2007 10:22 AM: > The symptoms are those of not capturing in promiscuous mode, I.e. you > see only broadcast packets and those directed to your machine (which > in this case do not exist). > >

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Luis EG Ontanon
The symptoms are those of not capturing in promiscuous mode, I.e. you see only broadcast packets and those directed to your machine (which in this case do not exist). Set the "Capture n promiscuous mode" flag in the capture dialog. On 10/10/07, Giles Coochey <[EMAIL PROTECTED]> wrote: > > > > Obv

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Giles Coochey
> > Obviously the port monitoring is incorrect. Cisco does a great job of > being inconsistent across their product line (but don't tell that to the > layer 3 guys - most insist Cisco can do no wrong as an article of faith). Are you sure that the port monitoring is wrong for a 3560? Maybe I'm mi

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Randy . Grein
y: [EMAIL PROTECTED] 10/10/2007 06:20 AM Please respond to Community support list for Wireshark To wireshark-users@wireshark.org cc Subject [Wireshark-users] Understanding what I'm seeing I'm currently using version 0.99.6 on a Windows platform. I have the following configuratio

Re: [Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Giles Coochey
> I'm currently using version 0.99.6 on a Windows platform. > > I have the following configuration set up on my Cisco 3560 switch. > > monitor session 1 source interface Gi0/21 (Windows XP Desktop) > monitor session 1 destination interface Gi0/22 (Windows XP Laptop > w/Wireshark application) >

[Wireshark-users] Understanding what I'm seeing

2007-10-10 Thread Chad Webb
I'm currently using version 0.99.6 on a Windows platform. I have the following configuration set up on my Cisco 3560 switch. monitor session 1 source interface Gi0/21 (Windows XP Desktop) monitor session 1 destination interface Gi0/22 (Windows XP Laptop w/Wireshark application) I start a capture