Wireshark supports name resolution in three layers:
- Layer 2: By resolving the first part of the MAC address to the vendor name. For example, 14:da:e9 will be presented as AsusTeckC (ASUSTeK Computer Inc.).
- Layer 3: By resolving IP addresses to the DNS names. For example, 157.166.226.46 will be resolved to www.edition.cnn.com.
- Layer 4: By resolving TCP/UDP port numbers to port names. For example, port 80 will be resolved as HTTP, and port 53 as DNS.
In the following screenshot, you can see how to configure name resolution in the Preferences window:
In this window, you can configure, from top to bottom: