Skip to main content
mhucm
New Member
August 29, 2018
Question

Diagnose sniffer packet MAC addresses

  • August 29, 2018
  • 4 replies
  • 12909 views

Any reason why displaying MAC addresses has not been implemented yet?

 

4 replies

darwin_FTNT
Staff
Staff
August 30, 2018

Using v5.6.5,build1600, in cli:

 

FW60EXXXXXXXXXXX # diagnose sniffer packet wifi 'ether[0:2] == 0xffff' 6 100 interfaces=[wifi] filters=[ether[0:2] == 0xffff] pcap_lookupnet: wifi: no IPv4 address assigned 1.610771 wifi -- arp who-has 192.168.1.254 tell 192.168.1.108 0x0000 ffff ffff ffff 4c11 bff4 04e0 0806 0001 ......L......... ............

 

 

sw2090
SuperUser
SuperUser
August 31, 2018

you could also save your capture into a textile (putty could e.g. do that) and convert it to pcap with some script you could find on the net and then open it in Wireshark to see mac addresses.

ede_pfau
SuperUser
SuperUser
August 31, 2018

Not a direct answer but maybe useful: to be able to filter on MACs you need to specify the 'ether' keyword. As already posted, where a part of the string is compared.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.