why does wireshark not change change the filter from tcp to udp when i monitor wireless traffic

  • retag add tags

i cannot change my fiter from tcp to udp when i monitor wireless traffic.

Faried's avatar
1
Faried
asked 2023-12-05 08:40:53 +0000
edit flag offensive 0 remove flag close merge delete

Comments

There are two kinds of filters, capture and display. Is this a display filter? Are you capturing wireless traffic in monitor mode or just capturing on the routed interface? If in monitor mode you may need to decrypt prior to observing the transport layer header.

Can you describe 'I cannot change'? You type the filter in the display filter field, press enter, and the box should turn green for either of those filters. Does it not do that? Or did you have some other expectation not met when you typed those strings into the filter box?

Bob Jones's avatar Bob Jones (2023-12-05 11:35:51 +0000) edit
add a comment see more comments