As it was already mentioned you can't sniff local traffic with protocol driver (like winpcap is), but you can do this using TDI filter. An example like this one http://www.ntkernel.com/w&p.php?id=24 based on http://www.ntkernel.com/w&p.php?id=8. Regards, Vadim