Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Packets in different VLANS flagged as duplicated Packets in RTP

From: John Powell <jrp999@xxxxxxxxx>
Date: Fri, 10 Aug 2012 06:48:39 -0600
Hi Everyone,

I am running Dumpcap as a service.

My users have told me that when they select a packet capture then select Telephony - RTP - Show all Streams that it indicates packets are being duplicated (negative packet loss).

For the packets being duplicated (negative packet loss), I discovered that there are in fact 2 packets being seen by Wireshark with the same SRC/DST IP Addresses and the same ID number BUT different VLANS tags. 

Is this an error in Wireshark that should be fixed or is there some way to configure Wireshark to look at the VLAN tag as well as the ID number before determining a packet is duplicated?

Thanx alot!

John