Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Duplicate packet with wireshark and winpcap

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Wed, 4 Oct 2006 16:20:13 -0700

On Wed, Oct 04, 2006 at 08:22:03PM +0200, alex loutrbringa' wrote:

> There is one millisecond each time between the two packets, the 
> packets are perfectly similar on ethernet, IP, TCP layers... Are the 
> packets really emitted two time or is this winpcap who capture 2 times 
> the packet?

This is most likely due to winpcap receiving two copies of the same data 
from Windows.  This happens due to extra drivers in the network control 
panel such as for VPNs or other packet sniffing programs.  Try 
unchecking the ones you don't need one-by-one until the problem goes 
away.


Steve


  • References:
    • [Wireshark-users] Duplicate packet with wireshark and winpcap
      • From: alex loutrbringa'
  • Prev by Date: [Wireshark-users] Hubs and Switches
  • Next by Date: Re: [Wireshark-users] Hubs and Switches
  • Previous by thread: [Wireshark-users] Duplicate packet with wireshark and winpcap
  • Next by thread: Re: [Wireshark-users] VoIP analysis and assessment
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation