Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Wireshark Packet Capture not working on Linux | Ubuntu | PopOs

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 5 Posters 842 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • manjotscM
      manjotsc
      last edited by manjotsc

      Screenshot from 2020-02-02 21-24-181.png

      link text

      Vendor: HP
      Version: P01 Ver. 02.50
      Release Date: Wed Jul 17 2024
      Boot Method: UEFI
      24.11-RELEASE (amd64)
      FreeBSD 15.0-CURRENT
      CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
      Current: 3606 MHz, Max: 3400 MHz
      4 CPUs : 1 package(s) x 4 core(s)

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        More info needed!

        pfSense version? OS you're connecting from? Wireshark version?

        Steve

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by

          I tend to run this 172.16.2.20 is the device I'm saving the capture file to:-

          andy@mac-pro ~ % ssh root@172.16.0.1 'tcpdump -i igb0 src not 172.16.2.20 and dst not 172.16.2.20 -w -' > ~/172.16.0.1.cap
          Password for root@pfsense:
          tcpdump: listening on igb0, link-type EN10MB (Ethernet), capture size 262144 bytes
          ^C% andy@mac-pro ~ %

          Then look at the capture after.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • manjotscM
            manjotsc
            last edited by manjotsc

            pfSense version = 2.4.4-RELEASE-p3
            OS you're connecting from = PopOS
            Wireshark version = Version 3.0.5 (Git v3.0.5 packaged as 3.0.5-1)

            Vendor: HP
            Version: P01 Ver. 02.50
            Release Date: Wed Jul 17 2024
            Boot Method: UEFI
            24.11-RELEASE (amd64)
            FreeBSD 15.0-CURRENT
            CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
            Current: 3606 MHz, Max: 3400 MHz
            4 CPUs : 1 package(s) x 4 core(s)

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              The syntax from the docs still works, I tried it today. A few things to watch out for: It assumes your shell is bash, that you have SSH keys and ssh-agent setup, that you are connecting to the firewall using the root account (e.g. root@192.168.1.1), and that wireshark is properly setup on your workstation. That likely includes making sure your user is a member of the wireshark group.

              Do not run ssh or wireshark with sudo on your workstation.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              manjotscM 2 Replies Last reply Reply Quote 2
              • manjotscM
                manjotsc @jimp
                last edited by

                @jimp How do I check if my shell is bash or not? I am new to Linux.

                Vendor: HP
                Version: P01 Ver. 02.50
                Release Date: Wed Jul 17 2024
                Boot Method: UEFI
                24.11-RELEASE (amd64)
                FreeBSD 15.0-CURRENT
                CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                Current: 3606 MHz, Max: 3400 MHz
                4 CPUs : 1 package(s) x 4 core(s)

                JKnottJ 1 Reply Last reply Reply Quote 0
                • JKnottJ
                  JKnott @manjotsc
                  last edited by

                  @manjotsc said in Wireshark Packet Capture not working:

                  @jimp How do I check if my shell is bash or not? I am new to Linux.

                  It's normally bash by default. So, unless you changed it, it's bash.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • manjotscM
                    manjotsc @jimp
                    last edited by manjotsc

                    @jimp Working I just changed admin@192.168.40.1 to root@192.168.40.1 , removed sudo and it worked.

                    Thanks,

                    Vendor: HP
                    Version: P01 Ver. 02.50
                    Release Date: Wed Jul 17 2024
                    Boot Method: UEFI
                    24.11-RELEASE (amd64)
                    FreeBSD 15.0-CURRENT
                    CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                    Current: 3606 MHz, Max: 3400 MHz
                    4 CPUs : 1 package(s) x 4 core(s)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.