Regarding the principle of ARP spoofing, is it all traffic or traffic of a specified protocol?

For example, I have a server with many rtsp protocol video streaming servers on the same network segment. They open the 80HTTP management port. I only want to intercept the 80HTTP management port password (because the administrator does not log in for a long time, I also I don’t know which one to log in, so I have to intercept all of them.) I am worried that capturing all the traffic to this server will cause the network to crash. Will this happen? :kissing:

Software used: cain, Bettercap

