
Destination address: wlan.Therefore it is not possible to use a capture. My take is that Wireshark capture filters use the Berkeley Packet Filter syntax, which does not have any functions for filtering by BLE hardware addresses. I have come to the, perhaps incorrect, conclusion that it is not possible. wlan.addr = 00:11:22:33:44:55 (Mac address) & wlan.fc.type_subtype = 0x0005 I have been crazy trying to use a capture filter on BLE traffic.wlan.addr = 00:11:22:33:44:55 (Mac address) & wlan.fc.type_subtype = 0x0000 Display filters allow us to compare fields within a protocol against a specific value, compare fields against fields and check the existence os specific fields or protocols.if there's a packet that has 172.22.21.

wlan.addr = 00:11:22:33:44:55 (Mac address) Do you mean that, if there's a packet that has 172.22.21.195 as its IP destination address and that has 00:50:56:b7:8d:f8 as its MAC source address, you wouldn't want to see it Or do you mean that both.Both Mac & Matt are currently studying for their final CWNP exam – CWAP! And have been making notes and tips along the way so we wanted to share some with you guys.Ī lot of these Wireshark filters below we got from the guys over at CTS but we have added a few more that we have found useful and we will keep adding along the way of our journey!
