Excluding or Including a Network/Subnet from Wireshark Results

You can use this wireshark filter to restrict results to the network you are interested in:

ip.addr ==

Since we are not specifying a source or destination (i.e. ip.src or ip.dst), the filter will match both. If you want to reverse it then:

!(ip.addr ==

I’ll often use the same method to filter the results on a specific IP address, preserving both ends of the conversation:

ip.addr ==

Written on May 18, 2013