ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] Packets not captured, tcp acking lost segments. Large pack

From: Andrew Hood <ajhood@xxxxxxxxx>
Date: Sun, 09 Jan 2011 16:12:56 +1100
Martin Visser wrote:
> Michael,
> 
> Just done a bit more googling and reading. Certainly this Microsoft
> customer service engineer thinks that a lot of problems are caused by
> Large Segment Offload  -
> http://blogs.msdn.com/b/psssql/archive/2010/02/21/tcp-offloading-again.aspx
> 
> There may be some value in turning this off, assuming it is on (at
> least for a test) and seeing whether Wireshark starts behaving and
> your application as well.

While trying to sort out TCP packets not reaching a target on the other
side of multiple firewalls we found we had to turn off LSO and TCP
chimney. Until we did that Wireshark saw only SYN, FIN and RST packets.

Since we haven't seen any noticable performance degradation, we have not
turned them back on.

Andrew
-- 
There's no point in being grown up if you can't be childish sometimes.
                -- Dr. Who