Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] Re: Removing duplicate frames via ip.id ?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: ronnie sahlberg <ronniesahlberg@xxxxxxxxx>
Date: Sat, 25 Jun 2005 17:38:11 -0400
I dont think there is a way to do this currently.


On 6/24/05, Barnaby DiAnni <bdianni@xxxxxxxxx> wrote:
> Hi,
> 
> Is there a way to filter out packets with duplicate IP Identifiers?  
> 
> Something along the lines of:
> 
> !ip.id.duplicate  ie..  "filter out non uniq ip.id packets" 
> 
> 
> Some sniffer captures often arrive with duplicate IP Identification due to
> the various ways that traffic can be spanned (mirrored) on a switch.
> 
> I'm aware of  
> 
> !tcp.analysis.duplicate_ack && !tcp.analysis.retransmission 
> 
> to filter these packets at the tcp layer.  But this may filter out valid
> retransmissions.
> 
> Thank you,
> 
> -- 
>     Barnaby 
> 
> _______________________________________________
> Ethereal-users mailing list
> Ethereal-users@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-users
>