Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] Duplicate packet with wireshark and winpcap

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "alex loutrbringa'" <castornightmare@xxxxxxxxx>
Date: Wed, 4 Oct 2006 20:22:03 +0200

Hi everybody,
i just installed last wireshark 0.99.3 with winpcap version 3.1 on my windows 2000 PC.
When i capture data from my Intel 8255x-Integrated ethernet interface, i see all the packets
emitted by my pc (source address is mine) twice.
So for all TCP ACK paquets, i've two entries :
*TCP ACK packet
*[TCP DUP ACK] packet
For all PSH ACK i've two entries :
*PSH ACK packet
*[TCP Out of Order] packet
There is one millisecond each time between the two packets, the packets are perfectly similar on ethernet, IP, TCP layers...
Are the packets really emitted two time or is this winpcap who capture 2 times the packet?
Thanks very much for any help.
Alex

  • Follow-Ups:
    • Re: [Wireshark-users] Duplicate packet with wireshark and winpcap
      • From: Stephen Fisher
  • Prev by Date: Re: [Wireshark-users] Question about parsing raw MTP3
  • Next by Date: Re: [Wireshark-users] Wireshark on OppenBSD 4.0
  • Previous by thread: [Wireshark-users] wide changes to the H248 dissector please test
  • Next by thread: Re: [Wireshark-users] Duplicate packet with wireshark and winpcap
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation