Giuseppe Larosa Fri, 06/19/2009 - 11:59

Hello Pedro,

first of all you need to mirror traffic o the PC NIC using some form on SPAN on a LAN switch.

then on wireshark after the capture you can select one frame of the TCP session and you can use the option called follow TCP stream it will open a child window trying to rebuild the TCP session

Hope to help



