Wireshark捕获数据包源IP显示为路由器IP的问题求助
Hey there, fellow Wireshark newbie! Let's figure out why you're seeing your router's IP (192.168.0.1) as the source instead of your own host IP when capturing ping traffic to google.com. I've been in your shoes before, so let's walk through some common fixes step by step:
1. Double-check your Wireshark capture interface
First things first—make sure you're capturing on the right network adapter of your own computer, not a virtual interface or something tied to your router.
- Open Wireshark, go to the Capture tab, and look at the list of interfaces. Pick the one you're actually using to connect to the internet (e.g.,
wlan0for Wi-Fi,eth0for wired). - Start capturing, run a
ping google.comin your terminal, then check the packets. Your ping request should have your host's local IP (like 192.168.0.x) as the source, not the router's.
2. Check if your host is doing local NAT (via iptables)
From the iptables -t nat -vnL screenshot you shared, we need to look for any SNAT rules that might be rewriting your outgoing traffic's source IP to your router's address.
- If you see a rule in the
POSTROUTINGchain that says something likeSNAT --to-source 192.168.0.1, that's the culprit! This means your computer is masquerading its traffic as the router's IP before it even leaves your machine. - To fix this, delete the rule with a command like:
Replaceiptables -t nat -D POSTROUTING -o [your-network-interface] -j SNAT --to-source 192.168.0.1[your-network-interface]with the actual interface name (e.g., eth0 or wlan0).
3. Disable IP forwarding if you don't need it
If your computer isn't acting as a router, having IP forwarding enabled can cause unexpected routing behavior.
- Check if it's turned on:
cat /proc/sys/net/ipv4/ip_forward - If the output is
1, turn it off temporarily:echo 0 > /proc/sys/net/ipv4/ip_forward - To make this permanent, edit
/etc/sysctl.conf, find the linenet.ipv4.ip_forward=1and change it tonet.ipv4.ip_forward=0, then runsysctl -pto apply the change.
4. Verify Wireshark's capture filter
It sounds silly, but sometimes accidental filters can hide the packets you want to see. Check the filter bar at the top of Wireshark—make sure there's no rule like ip.src == 192.168.0.1 that's only showing traffic from your router. Clear the filter (click the "X" or delete the text) and start capturing again.
If none of these fix it, could you share a bit more detail from your screenshots? For example, what's your host's local IP from ip addr show, and do you see any unusual rules in the nat/mangle tables?
内容的提问来源于stack exchange,提问作者Assad Rajab

