Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Duplicate packet with wireshark and winpcap

From: "alex loutrbringa'" <castornightmare@xxxxxxxxx>
Date: Wed, 4 Oct 2006 20:22:03 +0200
Hi everybody,
i just installed last wireshark 0.99.3 with winpcap version 3.1 on my windows 2000 PC.
When i capture data from my Intel 8255x-Integrated ethernet interface, i see all the packets
emitted by my pc (source address is mine) twice.
So for all TCP ACK paquets, i've two entries :
*TCP ACK packet
*[TCP DUP ACK] packet
For all PSH ACK i've two entries :
*PSH ACK packet
*[TCP Out of Order] packet
There is one millisecond each time between the two packets, the packets are perfectly similar on ethernet, IP, TCP layers...
Are the packets really emitted two time or is this winpcap who capture 2 times the packet?
Thanks very much for any help.
Alex