Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] Removing duplicate frames via ip.id ?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Barnaby DiAnni <bdianni@xxxxxxxxx>
Date: Fri, 24 Jun 2005 12:18:09 -0400
Hi,

Is there a way to filter out packets with duplicate IP Identifiers?  

Something along the lines of:

!ip.id.duplicate  ie..  "filter out non uniq ip.id packets" 


Some sniffer captures often arrive with duplicate IP Identification due to
the various ways that traffic can be spanned (mirrored) on a switch.

I'm aware of  

!tcp.analysis.duplicate_ack && !tcp.analysis.retransmission 

to filter these packets at the tcp layer.  But this may filter out valid
retransmissions.

Thank you,

-- 
    Barnaby