I will capturing the LAN.
How are the best practise to set filters?
If have a client 192.168.100.102. This client get an error if they will connect to itunes server.
How are the correct filter settings in wireshark (newest version), to run wireshark a long time, because the user ar not always online and can try it?
If I understand you right, you want to capture packets to understand why iTunes is throwing an error on a particular system? It looks like iTunes runs using port 80 and 443 for web traffic (based on wiki.wireshark.org/DisplayFilters. That may help you see how far the connection goes or may reveal firewall issues. Hope this helps.