Thanks for your reply, However the promiscuous mode function that I am after is a function of the Ethernet NIC hardware and driver not just the OS.
Wireshark allows the user to put network interface controllers that support promiscuous mode into that mode, in order to see all traffic visible on that interface, not just traffic addressed to one of the interface's configured addresses and broadcast/multicast traffic.
Anyone out there actually used/tested the thunderbolt Ethernet adapter to sniff traffic with wireshark (Ethereal), can you please if it can run in promiscuous mode ?
A friend and I just tested promiscuous mode on a MacBook Pro with Retina Display ("rMBP") using the Thunderbolt to Gigabit Ethernet adapter.
Test setup: rMBP and my MacBook Pro connected via Ethernet cables to a 10Base-T hub (old school!), plus a third Ethernet cable from the hub to the rest of the LAN. Running tcpdump on the rMBP, it was able to see all traffic between my MacBook Pro and the LAN.
He didn't have Wireshark/Ethereal installed so we didn't test that, but Wireshark uses the same mechanisms as tcpdump, so it should be fine.