Using WireShark to analyse communications on an Ethernet network

Using WireShark to analyse communications on an Ethernet network


General use of the Wireshark program.

Product Line

Access Expert, Andover Continuum, EcoStruxure Building Expert, EcoStruxure Building Operation, Pelco, Satchwell MicroNet, Satchwell Sigma, TAC IA Series, TAC INET, TAC Vista


Ethernet Networks


General Information on using WireShark.


Wireshark is an Ethernet packet analysis programme, Which can be downloaded from:

Installing Wireshark

  1. If necessary, unzip the WireShark executable file to a suitable location on the PC/Laptop you wish the programme to be installed on.
  2. Run the executable file and follow the on-screen instructions.

Rules for capturing LAN traffic using Wireshark:

Do not use a switch or router to connect the LAN capture PC to the network as these will filter important network activity that you will need to see. You will want to capture everything that is passing over the network at the point of concern. Usually, this means tapping into the ethernet at the Controller or controllers, that is having an issue.

midBit-Technologies-LLC-10-100 is an example of a device that can be used to easily tap into the network to take the capture.

The monitoring PC must see all traffic from the controller's point of view.

The monitoring PC can be connected in either two ways:

  1. Connected to the network at the controller
  2. The customers IT department can mirror all the network traffic from the controllers port to another port the PC can be connected to.

If connected to the network at the controllers, the connection must be made through a true ethernet hub. A hub will not selectively filter important network traffic as a switch or a router will do.

More information on what a "true ethernet hub" can be found at http://wiki.wireshark.org/HubReference

There are however some switches that feature port mirroring, please see How to Configure a NETGEAR Prosafe Plus Switch for Mirroring.

If connected to a mirrored port, the port must mirror 100% of the network traffic to and from the controller. No filtering should be done. Once a complete capture file has been obtained it can be filtered after the fact using WireShark or EtherReal.

Using Wireshark

  1. Run WireShark
  2. Start a trace by choosing the "Capture" menu and then select "Interfaces"
  3. Choose the appropriate interface. Generally, this can be identified by its IP Address, but if not, then the packets increasing are an indication.
  4. Press the "Start" button. The trace will start and will be similar to the following screenshot.
  5. After an appropriate time, the trace can be stopped by selecting "Capture" menu and "Stop"
  6. To save the capture file, choose "File" menu and "Save As".
Tags (2)
100% helpful (1/1)