data:image/s3,"s3://crabby-images/69d27/69d278c755df99374b99d95e0fe10b396e636604" alt="Mastering Wireshark 2"
Remote capture usage
In this section, we'll take a look at how to use that remote packet capture software that we set up with WinPcap on the remote system.
In order to use that remote WinPcap service running on the remote system and capture packets from it, we need to add that into our local Wireshark interface so that we can capture it. So in order to do this, we will perform the following steps:
- We will go ahead and click on Capture options icon.
- Click on Manage Interfaces... and you'll see here that there's the Remote Interfaces tab; click on that.
- Click on the plus icon in the bottom left-hand side here.
- Enter in the Host IP address of that remote system.
- Click on the Password authentication radio button, and enter in the credentials for that service account that we created. I used pcap here. You can then enter in the username and password and click on OK. At this point, it should show us the remote interfaces that it sees on the other device. So you see here that's my 5.25 device, and here's the interface that it detected:
data:image/s3,"s3://crabby-images/a12fc/a12fc6ca526f69353f709597d037a2aa71b03d26" alt=""
If you do not see this at this point, or you get a popup saying that you have some sort of connection error or it can't connect to the remote host, or anything like that, make sure that the service is running. Remember, when we set up the service on the remote system, it was on manual for the service—it was not automatic. So there's a good chance that the server's stopped or the system has rebooted, or something like that. Go over there and make sure that the service is enabled.
- So we go ahead and click on OK. You'll see that it shows in our interface list here. We can then go ahead and click on Start:
data:image/s3,"s3://crabby-images/42fa7/42fa71a81a2b6f3f412b5b98874e996d433d5dcc" alt=""
And that's all there is to it.