

Where the -i flags indicate which interface to capture, -a indicated the stop condition 10mb of capture) and -w is the output file. Information about the command line options is available here.

Since the wincap driver grabs packets as soon as they hit a port, before a software firewall can block them, Wireshark can monitor traffic on port 162 while MWExpertSystem is running. Unlike iReasoning's trap receiver, it is not necessary to stop the MWExpertSystem while troubleshooting when using Wireshark, which is useful when solving long-term or intermittent issues. This article describes how to verify the Barracuda RMM is parsing traps properly as they are received by the system it is installed on.
