EH-Net

Resources => Tools => Topic started by: SephStorm on January 27, 2012, 08:49:46 AM



Title: Wireshark question
Post by: SephStorm on January 27, 2012, 08:49:46 AM
Hi All,

I was viewing Laura's Lab Kit by Laura Chapell of WSU, in any case I skipped to the section regarding firewall rules, as FWs are something I have long held an interest in. In any case, Apparently the older version of WS had an option to create firewall rules from pcaps. I cannot find this functionality in the current version, does anyone know if this has been removed or simply moved?

The method is described here:
http://chrissanders.org/2008/08/wireshark-quick-tip-creating-firewall-acl-rules/


Title: Re: Wireshark question
Post by: hayabusa on January 27, 2012, 09:14:20 AM
Unsure...  I'm running Wireshark 1.6.2 on some lab machines, and the functionality is there for me.  :)

Edit:  But it's not in the same place...  I go to Tools > Firewall ACL Rules (not Analyze > Firewall ACL Rules, as your URL showed...)


Title: Re: Wireshark question
Post by: ajohnson on January 27, 2012, 09:33:07 AM
Yea, it's the first option under tools. You need to have a packet selected in a capture to enable the option.


Title: Re: Wireshark question
Post by: SephStorm on January 29, 2012, 01:38:02 PM
All correct, it was indeed moved.  ;D