Using Wireshark to Capture Network Traffic

The easiest way to capture network traffic is to use the build in capture feature of the 3CX Mangement Console which is elaborated here: If the need however arises to capture differently use the howto guide below:

  1. Download the latest version of Wireshark from There are 32-bit and 64-bit versions – make sure to download the correct version.
  2. Install and start Wireshark.
  3. Go to “Capture” > “Interfaces”. This shows a list of network interfaces found on the server. You will need to select the network interface that you would like to capture traffic from. The IP addresses may be shown in IPv6. Click on the IP address to show IPv4 address assigned to the NIC card.
    Wireshark_ Capture Interfaces
  4. Select the interface that you wish to capture traffic from and click on the “Options” button.
  5. Untick “Capture Traffic in promiscuous mode”, and leave all the other settings as default. Click the “Start” button to start the network capture.
    Wireshark_ Capture Options
  6. Reproduce the issue, noting the following were applicable:
    • Called number.
    • Calling number.
    • Extension numbers.
    • Any other entities, internal or external involved in replicating the issue.
    • The exact time the issue was replicated. You need to get this from the clock on the server running 3CX Phone System.
    • The route taken by the call.
    • Any other information you think could be relevant.
  7. Once the problem has been reproduced, you can stop the network capture from “Capture” > “Stop” (or by clicking the stop button  wireshark stop)
  8. You need to save the network capture from “File” > “Save As”.
  9. Give a name to the network capture. Leave the “Save as type” as default.
  10. Attach the Wireshark network capture file to the support ticket together with the 3CX Phone System support files.