ProfiShark Manager — Filters

The Filters Tab gives access to the ProfiShark 10G/10G+ hardware filters and deep packet inspection (DPI) feature. When enabled, only the packets matching the criteria configured in these filters and DPI will be captured in Live Capture and Direct Capture. These filters only affect the captured traffic and do not interfere with the counters displayed in the Counters Tab.

The Packet type section allows you to include or exclude packets based on their type. Selected packet types will be included in the capture, and unselected packet types will be excluded.

The Filter section allows filtering on Ethernet MAC, IPv4/6 addresses, and TCP/UDP ports.

The Deep Packet Inspection section allows users to search for a particular string (up to 16 characters in length) in the packets. This procedure is performed in real time, even at 20 Gbps. The left field accepts hexadecimal characters, while the right field accepts ASCII characters.

Note: Not all hexadecimal characters can be displayed in the ASCII field.

In the example above, ProfiShark has been set to capture only packets originating from or destined to any MAC address ending with 00, originating from or destined to any IPv4 address starting with 192.168, using port 443 for either incoming or outgoing traffic, and carrying matching DPI strings in their payload.

  • Last modified: March 21, 2024