Check out these great references as well:
|Our custom profiles repository for Wireshark|
Here is another Wireshark (TM) usage tip!
Normally, and by default, Wireshark captures packets and displays IP addresses of the devices that are sources and destinations:
During troubleshooting, it may be very advantageous to resolve IP addresses so that you can see domain names.
You should be aware that if you turn this on, that Wireshark now needs to look up each domain name! This will pollute the capture traffic with DNS requests that normally would not have been present.
So how do you turn this feature on?
It is easy. Go to Edit> Settings, and the following dialogue appears:
Now select the Name Resolution item under User Interface, and your display looks like this:
Note the "Enable network name resolution" check box is unchecked. Yet MAC name resolution may be checked, etc.
Click on the check box to enable the Network (Layer 3 IP) name resolution and click OK.
Note how our Wireshark display has already been altered (you may have to click the refresh/reload icon):
Very handy. Comments are welcomed.