Friday, August 1, 2014

Network layer name resolution in Wireshark

Normally Wireshark does not make a reverse lookup for network layer addresses, which makes it sometime hard to find out to which communication a IP packet belongs.

Wireshark main window

Fortunately there is an option to enable the name resolution for the network layer. Just select the  "View->Name Resolution->Enable for Network Layer" option.

Enable Name Resolution for Wirshark

Now every IP Address which has a DNS name assigned, will be automatically resolved in your network trace.

Wireshark shows now network names

No comments:

Post a Comment