Skip to main content

Packet Capture with Wireshark

Install and prepare Wireshark​

Download Wireshark from its official website. The older Windows setup illustrated below uses WinPcap. Use wired Ethernet for that setup: WinPcap may not capture Wi-Fi correctly, while AirPcap is a commercial alternative.

If a legacy capture setup fails on Windows 10 build 1607 or NDIS 6 and later, the original troubleshooting options include Win10Pcap or Npcap.

Before capturing a new game's traffic, close browsers, torrents, downloads and other programs that generate unrelated traffic. This keeps the file smaller and makes analysis easier.

Capture controls in older Wireshark versions​

  1. Click “List the available capture interfaces”.

    Capture-interface list button in Wireshark 1.6.4

  2. Select the physical adapter connected to the Internet. Its packet count normally keeps increasing. “TAP-Win32 Adapter V9” is Mudfish's virtual adapter; the Intel Ethernet adapter in this example is the physical one. Your adapter name may differ. Click “Start” next to the intended adapter.

    Available capture interfaces and Start buttons

  3. Play with other users while capturing. A capture made without actual gameplay is not useful for registering the game.

  4. Click “Stop the running live capture”, then use “File → Save”.

    Stop capture button in Wireshark 1.6.4

How to​

There are multiple tutorials available on the internet about how to capture packets using Wireshark as follows:

Instruction​

Register new game​

If you'd like to register game you're playing at Mudfish. Please follow below:

  1. (Optional) Stop all programs which make any network activities.

  2. Stop Mudfish program also.

  3. Run Wireshark and start to capture packets against network device which is connected with the internet line.

  4. Play a game with other users (important).

  5. Stop to capture and save to the file.

  6. Sends the packet dump file to support@loxch.com

Dump missed IP blocks for mudfish item​

Sometimes the technician of mudfish asks you to do the packet dump to get the missed IP blocks if the mudfish item doesn't work properly. Then please try to do as follows:

  1. Disable Full VPN mode first.

  2. Run Wireshark and start the packet dump. However please perform a dump for the network interface which connects with your ISP. Please don't dump TAP-Win32 adapter v9 because we're looking for missed IP blocked.

  3. Please make sure that your items are enabled and run the mudfish launcher. And please wait until your configuration is applied.

  4. Progress your steps until the problem is reproduced while Wireshark is doing the packet dump.

  5. When it's reproduced, stop to capture and save to the file.

  6. Sends the packet dump file to support@loxch.com

warning

Packet captures can contain sensitive information. Email the file to support@loxch.com; do not upload it to a public forum topic.