{"id":3087,"date":"2024-01-04T11:47:04","date_gmt":"2024-01-04T11:47:04","guid":{"rendered":"https:\/\/wordpress.pedrorotoli.com\/?p=3087"},"modified":"2024-01-04T11:47:04","modified_gmt":"2024-01-04T11:47:04","slug":"remote-capture-with-wireshark-and-mikrotik","status":"publish","type":"post","link":"https:\/\/wordpress.pedrorotoli.com\/?p=3087","title":{"rendered":"Remote Capture With Wireshark and Mikrotik"},"content":{"rendered":"<p>Using Winbox access the Mikrotik router, then on <em>Tools<\/em>, open <em>Packet Sniffer<\/em>.<\/p>\n<figure id=\"attachment_3088\" aria-describedby=\"caption-attachment-3088\" style=\"width: 267px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3088\" src=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-tools-packet_sniffer.png\" alt=\"Packet Sniffer location on Winbox\" width=\"267\" height=\"452\" \/><figcaption id=\"caption-attachment-3088\" class=\"wp-caption-text\">Packet Sniffer location on Winbox<\/figcaption><\/figure>\n<p>Then, on the Packet Sniffer window, open the Streaming tab.<\/p>\n<figure id=\"attachment_3089\" aria-describedby=\"caption-attachment-3089\" style=\"width: 537px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3089\" src=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-streaming.png\" alt=\"Packet Sniffer on Mikrotik\" width=\"537\" height=\"528\" srcset=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-streaming.png 537w, https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-streaming-512x503.png 512w\" sizes=\"auto, (max-width: 537px) 100vw, 537px\" \/><figcaption id=\"caption-attachment-3089\" class=\"wp-caption-text\">Packet Sniffer on Mikrotik<\/figcaption><\/figure>\n<p>Select the option <em>Streaming Enabled<\/em>, on <em>Server<\/em> put the IP of the machine that will be running Wireshark, on <em>Port<\/em> you can leave as is or specify a different port, then open the <em>Filter<\/em> tab.<\/p>\n<figure id=\"attachment_3091\" aria-describedby=\"caption-attachment-3091\" style=\"width: 533px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3091\" src=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-filter.png\" alt=\"Mikrotik Packet Sniffer Filter\" width=\"533\" height=\"551\" srcset=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-filter.png 533w, https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Mikrotik-packet_sniffer-filter-495x512.png 495w\" sizes=\"auto, (max-width: 533px) 100vw, 533px\" \/><figcaption id=\"caption-attachment-3091\" class=\"wp-caption-text\">Mikrotik Packet Sniffer Filter<\/figcaption><\/figure>\n<p>Select the interface that you wish to perform the capture, here you can specify a multitude of filters, if you wish to reduce the traffic sent over to the PC that will perform the capture.<\/p>\n<p>After everything is configured correctly, click <em>Apply<\/em> then <em>Start<\/em>.<\/p>\n<p>Now on to Wireshark.<\/p>\n<figure id=\"attachment_3092\" aria-describedby=\"caption-attachment-3092\" style=\"width: 662px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3092\" src=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark-select_interface_and_filter.png\" alt=\"Wireshark Interface and filter selection\" width=\"662\" height=\"425\" srcset=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark-select_interface_and_filter.png 662w, https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark-select_interface_and_filter-512x329.png 512w\" sizes=\"auto, (max-width: 662px) 100vw, 662px\" \/><figcaption id=\"caption-attachment-3092\" class=\"wp-caption-text\">Wireshark Interface and filter selection<\/figcaption><\/figure>\n<p>On Wireshark, select the interface where you will receive the capture stream, and use the filter <strong>udp port &lt;port number specified earlier&gt;<\/strong>, then double click on the interface selected previously, this will start the capture on Wireshark.<\/p>\n<figure id=\"attachment_3093\" aria-describedby=\"caption-attachment-3093\" style=\"width: 1212px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3093\" src=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark_capture_running.png\" alt=\"Remote Wireshark capture running\" width=\"1212\" height=\"566\" srcset=\"https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark_capture_running.png 1212w, https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark_capture_running-512x239.png 512w, https:\/\/wordpress.pedrorotoli.com\/wp-content\/uploads\/2024\/01\/Wireshark_capture_running-768x359.png 768w\" sizes=\"auto, (max-width: 1212px) 100vw, 1212px\" \/><figcaption id=\"caption-attachment-3093\" class=\"wp-caption-text\">Remote Wireshark capture running<\/figcaption><\/figure>\n<p>And with this you can make remote captures on Wireshark.<\/p>\n<p>Just don&#8217;t forget to also stop the capture on the Mikrotik when you are finished.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using Winbox access the Mikrotik router, then on Tools, open Packet Sniffer. Then, on the Packet Sniffer window, open the Streaming tab. Select the option<\/p>\n","protected":false},"author":1,"featured_media":3094,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/posts\/3087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3087"}],"version-history":[{"count":2,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/posts\/3087\/revisions"}],"predecessor-version":[{"id":3095,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/posts\/3087\/revisions\/3095"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=\/wp\/v2\/media\/3094"}],"wp:attachment":[{"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.pedrorotoli.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}