
To start the packet capturing process, click the Capture menu and choose Start.

To set a filter, click the Capture menu, choose Options, and click WireShark: Capture Filter will appear where you can set various filters. In this case, you can set a filter that excludes all packets except those associated with the IP address of the client you’re troubleshooting. For example, you may be troubleshooting a particular client device connecting to the network. The menu Advanced Wireless Settings will appear where you can change the channel.Ĭonsider filtering the packet capture to reduce clutter when analyzing packet traces. To do this, click the Capture menu, choose Options, and click Wireless Settings. For example, if the wireless network is set to channel 1 for the traffic you’re interested in, then configure WireShark to monitor channel 1. To select an interface, click the Capture menu, choose Options, and select the appropriate interface.īe certain to monitor the correct RF channel. An external antenna is also included with AirPcap, which increases the listening ability of the tool.īefore capturing packets, configure WireShark to interface with an 802.11 client device otherwise, you’ll get an alert “No capture interface selected!” when starting a packet capture. It comes with drivers tuned to WireShark and operates very well. If you have trouble getting WireShark working with existing client cards, then consider purchasing AirPcap, which is a USB-based 802.11 radio designed to work effectively with WireShark. In this case, you can try turning promiscuous mode off (from inside WireShark), but you’ll only see (at best) packets being sent to and from the computer running WireShark.


The issue is that many of the 802.11 cards don’t support promiscuous mode. Simply go to, download the software for your applicable operating system, and perform the installation.Ī problem you’ll likely run into is that WireShark may not display any packets after starting a capture using your existing 802.11 client card, especially if running in Windows. Ethereal doesn’t appear to be supported anymore, so use WireShark instead. WireShark provides the same (if not better) functionality as Ethereal. Over a year ago, however, Ethereal’s lead developer (Gerald Combs) re-released the software as WireShark. You may be familiar with using Ethereal software for sniffing wireless networks. WireShark is freely-available software that interfaces with an 802.11 client card and passively captures (“sniffs”) 802.11 packets being transmitted within a wireless LAN. Learn tips on configuring and using this tool when analyzing and troubleshooting 802.11 wireless networks.

WireShark is free software that sniffs packets on wireless networks.
