We're now a non-profit! Support open source packet analysis by making a donation.

Wireshark-users: Re: [Wireshark-users] Wireshark-users Digest, Vol 4, Issue 35

From: "Sean Baker" <[email protected]>
Date: Thu, 28 Sep 2006 11:36:49 -0400
On 9/28/06, "ronnie sahlberg" <[email protected]> wrote:

It looks like you capture all outgoing packets twice some 30us apart.

Is this captured on windows hosts? do you use something like BlackIce on
that windows host?

There is some interaction between tools such as BlackIce and the capture
process on windows that sometimes lead to the outgoing packets being
captured twice in exactly this manner.

Both hosts were running WinXP. There is a AES NDIS Filter Driver that provides encryption for the mesh network, maybe that is what is causing the problem. I'm not sure what else it could be.

Is there a filter that I can use to block out the duplicate packets?