Question: Filtering the Display Note : If you are using WireShark from within VCASTLE, you will need to open Canvas launch this activity so that you
Filtering the Display
Note: If you are using WireShark from within VCASTLE, you will need to open Canvas launch this activity so that you can downloaduser.cap.It is permissible to download and install WireShark on your PC.In this case, you would need to download theuser.capto your local PC.
The capture file will often contain a number of packets that have little use to you in analyzing traffic. By filtering the display you can limit the packets displayed to only those that meet specific criteria. Some common criteria used to filter traffic are protocols, IP addresses, and MAC addresses.
The criteria can include any value that exists in one of the headers.
- Download and open theuser.capwith WireShark. This file contains a capture with some traffic from a user accessing the Internet.
- In theFilterbox, just below the menu, enter inHTTP, notice that the program will attempt to auto-complete the filter based on what you type in. The background color will turn to green when you have entered a valid value for the filter. Click the apply button to apply the filter.
- How many packets are now displayed?Answer
- Filter the traffic so that onlyDNStraffic is displayed.
- What did you type in the filter box?Answer
- How many packets are displayed?Answer
- Filter the traffic so that onlyFTPtraffic is displayed.
- What did you type in the filter box?Answer
- How many packets are displayed?Answer
- To filter by a specific IP address, typeip.addr==followed by the IP address. This will look at the source or destination address in the IP header.
- Typeip.addr==66.35.45.201
- How many packets are displayed?Answer
- Type in "ip." in the filter field to show the possible completions for the IP header.
- What would you have to enter in the filter box to display only those packets whose destination IP address was equal to74.125.93.100?Answer
- If you are filtering, remove filter by clickXon the right side of the filter input box. In Frame 1, in thePacket detailspane, expandEthernet II.What is the Source MAC address?Answer
- If this frame went through a network hub, would the Source MAC change?Answer
- Yes
- No
- If this frame went through a network switch, would the Source MAC change?Answer
- Yes
- No
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
