Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] Bogus IP Header

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Fri, 17 Jun 2005 21:11:18 -0700
Gordon Graham wrote:
I just installed Ethereal today and am having trouble capturing packets properly. I am able to capture a series of packets but almost every one says "Bogus IP length 0 ..." or Bogus IP header ...".

In the packet details area the Frame information says something like (1514 bytes on wire, 28 bytes captured). Different frames have a different number of "bytes on the wire" but all seem to say 28 bytes captured. I've tried promiscuous mode and not promiscuous mode with the same results. Otherwise, I'm using all the default values.

I'm running on a Windows ME laptop

This is probably a WinPcap problem, and I suspect it might be a problem with some other software on your system. You should ask the WinPcap developers about this:

	http://www.winpcap.org/contact.htm