Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Seeing Preamble in Decodes

From: "Gross, Pete" <pgross@xxxxxxxxxxxxxx>
Date: Wed, 28 Mar 2007 21:18:27 -1000
I was able to figure out that for some reason the hardware was attaching its
own preamble (when I thought it wasn't).  I had an idea that this was
actually happening, but was not having much luck in tracking it down.  So,
as two preambles were being transmitted I was seeing the 2nd one.
Thanks for the offer to help.

Pete


On 3/27/07 4:12 PM, "Guy Harris" <guy@xxxxxxxxxxxx> wrote:

> 
On Mar 23, 2007, at 1:34 PM, Gross, Pete wrote:

> I am just wondering why I
> would start seeing the preamble in some of  
> the decodes of packets, yet not
> in all of them?  At first I thought  
> maybe I was transmitting two
> preambles, but as far as I can tell I  
> am not.  I thought that the hardware
> would take care of the preamble  
> and this wouldn¹t be seen in wireshark at
> all (as the preamble is  
> not seen in other decodes).  Any help or ideas on
> why this could  
> possibly be happening would be very helpful (and might even
> let me  
> stop banging my head against the wall).

What network type is this
> on?  Ethernet?

What type of hardware and software did you use to capture the
> traffic?

Can you send us an example of a capture showing this problem?

If
> not, can you send us a (possibly censored) example of Wireshark/ 
TShark
> displaying the preamble?  (Please use the "Export" menu of  
Wireshark, and
> export as plain text, or use "tshark -V" to produce a  
text example - you can
> edit the text if you don't want IP or MAC  
addresses, for example, displayed;
> don't send a screen shot - mail  
messages with screen shots are much bigger
> than mail messages with  
just text, and are slower to download especially
> over slower links,  
*and* they're probably harder to
> censor.)
_______________________________________________
Wireshark-users
> mailing 
> list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/w
> ireshark-users



<DIV><FONT size="1">

E-mail confidentiality.
--------------------------------
This e-mail contains confidential and / or privileged information belonging to Spirent Communications plc, its affiliates and / or subsidiaries. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution and / or the taking of any action based upon reliance on the contents of this transmission is strictly forbidden. If you have received this message in error please notify the sender by return e-mail and delete it from your system. If you require assistance, please contact our IT department at helpdesk@xxxxxxxxxxx.

Spirent Communications plc,
Spirent House, Crawley Business Quarter, Fleming Way, Crawley, West Sussex, RH10 9QL, United Kingdom.
Tel No. +44 (0) 1293 767676
Fax No. +44 (0) 1293 767677

Registered in England Number 470893
Registered at Spirent House, Crawley Business Quarter, Fleming Way, Crawley, West Sussex, RH10 9QL, United Kingdom 

Or if within the US,

Spirent Communications,
26750 Agoura Road, Calabasas, CA, 91302, USA.
Tel No. 1-818-676- 2300 

</FONT></DIV>