Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Capturing up 64K byte frame on a VM guest

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Saulpaugh, Chris" <Chris.Saulpaugh@xxxxxxxxxxxxx>
Date: Wed, 17 Mar 2010 12:01:03 -0700

Hi all,

There is an option on the NIC to enable or disable Large Frame Offload. This will impact how packets are passed to the NIC from the OS. With this disabled, all frames sent will be per the MSS allowed on the physical infrastructure and will be recorded as such in your capture tool. With this enabled, large frames up to 64k will be passed to the NIC and then the NIC will handle the segmentation and get it on the wire (this you won't see in your capture).

I'm running into issues with this and troubleshooting network issues on Windows 2008 rtm/r2 servers and VMs. Though I can't say at this point that this is impacting communications.

Cheers,



  • Prev by Date: Re: [Wireshark-users] TShark Error
  • Next by Date: Re: [Wireshark-users] TShark Error
  • Previous by thread: Re: [Wireshark-users] Capturing up 64K byte frame on a VM guest
  • Next by thread: [Wireshark-users] AirPcap Nx and Windows 7 64 Bit Produces Wireshark Crash
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation