Basic Wireshark Layer 3 Name Resolution

Check out these great references as well: 

 Our custom profiles repository for Wireshark
 Our Udemy course on Wireshark 
 Our Udemy course on Wireless Packet capture

Here is another Wireshark (TM) usage tip!

Normally, and by default, Wireshark captures packets and displays IP addresses of the devices that are sources and destinations:

During troubleshooting, it may be very advantageous to resolve IP addresses so that you can see domain names.

You should be aware that if you turn this on, that Wireshark now needs to look up each domain name!  This may pollute the capture traffic with DNS requests that normally would not have been present if you turn on name resolution while capturing.  The default is that this is turned off.

So how do you turn this feature on?

It is easy.  Go to Edit> Settings, and the following dialogue appears:

Now select the Name Resolution item under User Interface, and your display looks like this:

Note the “Enable network name resolution” check box is unchecked.  Yet MAC name resolution may be checked, etc.

Click on the check box to enable the Network (Layer 3 IP) name resolution and click OK.

Note how our Wireshark display has already been altered (you may have to click the refresh/reload icon):


Very handy. 

What if you wanted to customize this name resolution?  Check out our article on customizing hame resolution here.

I hope you find this article and its content helpful.  Comments are welcomed below.  If you would like to see more articles like this, please support us by clicking the patron link where you will receive free bonus access to courses and more, or simply buying us a cup of coffee!, and all comments are welcome! 

Leave a Comment

Contact Us Here

Please verify.
Validation complete :)
Validation failed :(
Your contact request has been received. We usually respond within an hour, but please be patient. We will get back to you very soon.
Scroll to Top