Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] Sent packets captured twice

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Andrew Hood <ajhood@xxxxxxxxx>
Date: Thu, 26 May 2005 23:38:44 +1000
Guy Harris wrote:
Harry J Moyes wrote:

The issue occurs with all versions of Ethereal that we have tried on these systems recently and with both the production and latest release of WinPcap.


Does it happen with WinDump as well?

If so, it's probably a WinPcap issue.

I've been talking to Harry offline and we have some feedback. The problem affected all outbound packets, not just ICMP.

The IBM T40 Thinkpad has an Intel PRO 1000/MT built in. Harry and I were both running drivers from Intel we got last year sometime. We found that if you disabled "Net Firewall" in the driver config the duplicated packets stopped.

I have an EtherJet 10/100 PCMCIA card with Microsoft drivers. This did not duplicate packets with "Net Firewall" enabled.

At this point I started to suspect the non-Microsoft driver, and that the tap point was being passed twice for outbound packets if you had "Net Firewall" enabled.

I upgraded the drivers to the latest ones on the Intel site (8.5.14.0). The duplication stopped.

Just when I thought all was well, Harry tells me that upgrading the drivers has not fixed it for him.

--
There's no point in being grown up if you can't be childish sometimes.
                -- Dr. Who