Wireshark mailing list archives

Re: Windows dumpcap -i TCP@<IP>


From: Anders Broman <anders.broman () ericsson com>
Date: Tue, 18 Sep 2018 07:27:10 +0000

What version of Wireshark and what Linux version on the remote side? I think some work has ben done on rpcap recently 
so trying out the development version
is an option. https://www.wireshark.org/download/automated/win64/
Regards
Anders

From: Wireshark-dev <wireshark-dev-bounces () wireshark org> On Behalf Of James Ko
Sent: den 18 september 2018 02:22
To: wireshark-dev () wireshark org
Subject: [Wireshark-dev] Windows dumpcap -i TCP@<IP>


Hi,



I am trying to connect to a remote PCAPNG stream from Windows using the TCP@ socket interface but the connection closes 
immediately after connecting.  The same dumpcap command on linux works just fine to the remote TCP socket.



No errors indicating any failure are printed from dumpcap.exe

C:\>"\Program Files\Wireshark\dumpcap.exe" -i TCP@192.168.1.100<mailto:TCP@192.168.1.100> -w -

Capturing on 'TCP@192.168.1.100'

dumcap:



C:\>



On the remote end running in linux I see a connect and disconnect with EPOLLHUP event.



Has anyone else tried or have remote TCP socket connections working with dumpcap in Windows?



James


___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: