Why Does wireshark not capture any traffic from Source Machine with Outbound Firewall Rules? (2024)

Hi,

I was testing on Windows 2008 Standard Edition (Local Machine IP :- 192.168.2.160) with normal windows firewall (no 3rd party) and created an outbound firewall rule to deny for TCP Ports 80/443 of Remote IP (i.e. 192.168.10.104) (and Local Port All as it could be random). The firewall worked fine and I could block all outbound traffic to Ports 80/443 of that remote IP. Traffic to same ports on any other remote IP worked just fine.

However I would have expected wireshark to have picked up the traffic initiation attempt at least from local PC/random ports and drops when matched against remote IP/Port that I have defined in the Outbound Rules.

== > However I could see absolutely no traffic for this when running wire shark on the Local PC where I had applied such a rule.

== > Checking the windows Firewall Logs I could see the Drops:-

2012-05-20 10:08:34 DROP TCP 192.168.2.160 192.168.10.104 49215 80 0 - 0 0 0 - - - SEND

2012-05-20 10:08:35 DROP TCP 192.168.2.160 192.168.10.104 49216 80 0 - 0 0 0 - - - SEND

== > So the windows firewall clearly shows the drops then why does that not reflect in the wireshark?

== > Is it because the Firewall is software based and the request was made via a browser that it never gets sent down beyond the network layer from the App layer of the same PC when Windows firewall and the PC in fact never sends the packet.

Or is there some setting on wire-shark that can allow such drops to show as well as we can see in the Firewall logs above.

The main reason for me to ask this I want to clarify the way this works as the traffic not showing could be an issue with:-

1.) An application as well which might not be able to invoke the lower layers and initiate from source itself. OR, 2.) It could be an issue with block as well like this and we would not be able to distinguish via packet captures b/w them and more so if no such logs / 3rd party unknown firewall apps are present.

== > I am not sure if I should have posted this concern in Windows forum or wireshark but since I could see nothing in wire-shark unlike in the Windows Firewall Logs.

Please suggest

Regards, Prad :)

asked 19 May '12, 22:00

Why Does wireshark not capture any traffic from Source Machine with Outbound Firewall Rules? (1)

im_prad
5114
accept rate: 0%

edited 19 May '12, 22:03

Why Does wireshark not capture any traffic from Source Machine with Outbound Firewall Rules? (2024)
Top Articles
Curve DAO (CRV) Price Prediction 2023, 2024, 2025, 2026 - 2030
Budget Set up
Navicent Human Resources Phone Number
No Hard Feelings Showtimes Near Metropolitan Fiesta 5 Theatre
Uihc Family Medicine
Nwi Police Blotter
Mlifeinsider Okta
Southland Goldendoodles
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Jcpenney At Home Associate Kiosk
Capitulo 2B Answers Page 40
Best Restaurants Ventnor
123Moviescloud
Top tips for getting around Buenos Aires
Maplestar Kemono
Blackwolf Run Pro Shop
Cocaine Bear Showtimes Near Regal Opry Mills
Long Island Jobs Craigslist
Aps Day Spa Evesham
Catherine Christiane Cruz
Babbychula
Betaalbaar naar The Big Apple: 9 x tips voor New York City
Knock At The Cabin Showtimes Near Alamo Drafthouse Raleigh
Drift Hunters - Play Unblocked Game Online
Soul Eater Resonance Wavelength Tier List
New Stores Coming To Canton Ohio 2022
Riverstock Apartments Photos
Log in to your MyChart account
Salemhex ticket show3
How often should you visit your Barber?
Lincoln Financial Field, section 110, row 4, home of Philadelphia Eagles, Temple Owls, page 1
Devotion Showtimes Near The Grand 16 - Pier Park
140000 Kilometers To Miles
Capital Hall 6 Base Layout
Newsday Brains Only
Green Bay Crime Reports Police Fire And Rescue
No Hard Feelings Showtimes Near Tilton Square Theatre
A Man Called Otto Showtimes Near Amc Muncie 12
Afspraak inzien
Qlima© Petroleumofen Elektronischer Laserofen SRE 9046 TC mit 4,7 KW CO2 Wächter • EUR 425,95
Craigslist En Brownsville Texas
Low Tide In Twilight Manga Chapter 53
Union Corners Obgyn
Kenner And Stevens Funeral Home
Levi Ackerman Tattoo Ideas
Love Words Starting with P (With Definition)
St Anthony Hospital Crown Point Visiting Hours
Call2Recycle Sites At The Home Depot
The Significance Of The Haitian Revolution Was That It Weegy
211475039
Latest Posts
Article information

Author: Terrell Hackett

Last Updated:

Views: 5476

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.