• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] Wireshark Packet Capture not working on Linux | Ubuntu | PopOs

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 5 Posters 817 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    manjotsc
    last edited by manjotsc Feb 7, 2020, 4:44 AM Feb 3, 2020, 2:37 AM

    Screenshot from 2020-02-02 21-24-181.png

    link text

    Vendor: HP
    Version: P01 Ver. 02.50
    Release Date: Wed Jul 17 2024
    Boot Method: UEFI
    24.11-RELEASE (amd64)
    FreeBSD 15.0-CURRENT
    CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
    Current: 3606 MHz, Max: 3400 MHz
    4 CPUs : 1 package(s) x 4 core(s)

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Feb 3, 2020, 12:52 PM

      More info needed!

      pfSense version? OS you're connecting from? Wireshark version?

      Steve

      1 Reply Last reply Reply Quote 0
      • N
        NogBadTheBad
        last edited by Feb 3, 2020, 2:36 PM

        I tend to run this 172.16.2.20 is the device I'm saving the capture file to:-

        andy@mac-pro ~ % ssh root@172.16.0.1 'tcpdump -i igb0 src not 172.16.2.20 and dst not 172.16.2.20 -w -' > ~/172.16.0.1.cap
        Password for root@pfsense:
        tcpdump: listening on igb0, link-type EN10MB (Ethernet), capture size 262144 bytes
        ^C% andy@mac-pro ~ %

        Then look at the capture after.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • M
          manjotsc
          last edited by manjotsc Feb 3, 2020, 9:25 PM Feb 3, 2020, 9:23 PM

          pfSense version = 2.4.4-RELEASE-p3
          OS you're connecting from = PopOS
          Wireshark version = Version 3.0.5 (Git v3.0.5 packaged as 3.0.5-1)

          Vendor: HP
          Version: P01 Ver. 02.50
          Release Date: Wed Jul 17 2024
          Boot Method: UEFI
          24.11-RELEASE (amd64)
          FreeBSD 15.0-CURRENT
          CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
          Current: 3606 MHz, Max: 3400 MHz
          4 CPUs : 1 package(s) x 4 core(s)

          1 Reply Last reply Reply Quote 0
          • J
            jimp Rebel Alliance Developer Netgate
            last edited by Feb 3, 2020, 9:27 PM

            The syntax from the docs still works, I tried it today. A few things to watch out for: It assumes your shell is bash, that you have SSH keys and ssh-agent setup, that you are connecting to the firewall using the root account (e.g. root@192.168.1.1), and that wireshark is properly setup on your workstation. That likely includes making sure your user is a member of the wireshark group.

            Do not run ssh or wireshark with sudo on your workstation.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            M 2 Replies Last reply Feb 3, 2020, 9:31 PM Reply Quote 2
            • M
              manjotsc @jimp
              last edited by Feb 3, 2020, 9:31 PM

              @jimp How do I check if my shell is bash or not? I am new to Linux.

              Vendor: HP
              Version: P01 Ver. 02.50
              Release Date: Wed Jul 17 2024
              Boot Method: UEFI
              24.11-RELEASE (amd64)
              FreeBSD 15.0-CURRENT
              CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
              Current: 3606 MHz, Max: 3400 MHz
              4 CPUs : 1 package(s) x 4 core(s)

              J 1 Reply Last reply Feb 3, 2020, 9:33 PM Reply Quote 0
              • J
                JKnott @manjotsc
                last edited by Feb 3, 2020, 9:33 PM

                @manjotsc said in Wireshark Packet Capture not working:

                @jimp How do I check if my shell is bash or not? I am new to Linux.

                It's normally bash by default. So, unless you changed it, it's bash.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • M
                  manjotsc @jimp
                  last edited by manjotsc Feb 3, 2020, 9:50 PM Feb 3, 2020, 9:37 PM

                  @jimp Working I just changed admin@192.168.40.1 to root@192.168.40.1 , removed sudo and it worked.

                  Thanks,

                  Vendor: HP
                  Version: P01 Ver. 02.50
                  Release Date: Wed Jul 17 2024
                  Boot Method: UEFI
                  24.11-RELEASE (amd64)
                  FreeBSD 15.0-CURRENT
                  CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
                  Current: 3606 MHz, Max: 3400 MHz
                  4 CPUs : 1 package(s) x 4 core(s)

                  1 Reply Last reply Reply Quote 0
                  1 out of 8
                  • First post
                    1/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received