Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Conflict with Cisco VPN?

From: "Mark McWhinney" <msm@xxxxxxxxxxx>
Date: Tue, 22 May 2007 15:24:24 -0700
Hello,

Recently I installed Ethereal 0.99 / WinPcap 3 then upgraded to the current
Wireshark 0.99.5 / WinPcap 4 on my Windows XP Pro laptop.

I have been using Cisco VPN for a while without any trouble.  Now, the VPN
does not work on my network card but does work with my Wireless connection.

Is it possible that Ethereal/Wireshark/WinPcap damaged a driver or something
else that would muck up my TCP packets?

I uninstalled Ethereal/Wireshark/WinPcap and re-installed the Cisco VPN
client but am still getting the same results.

Any tips or pointers?


The following is a snip from the VPN log:

11     10:02:23.382  05/22/07  Sev=Info/4	CM/0x63100029
TCP connection established on port 44233 with server "bulldog.ABC.com"

12     10:02:23.882  05/22/07  Sev=Info/4	CM/0x63100024
Attempt connection with server "bulldog.ABC.com"

13     10:02:24.882  05/22/07  Sev=Info/6	IPSEC/0x63700023
CNIReceiveComplete: Invalid TCP checksum

14     10:02:24.882  05/22/07  Sev=Warning/3	IPSEC/0xA370001C
Bad cTCP trailer, Rsvd 0, Magic# 0h, trailer len 0, MajorVer 0, MinorVer 0

15     10:02:29.881  05/22/07  Sev=Info/4	CM/0x63100014
Unable to establish Phase 1 SA with server "bulldog.24hourfit.com" because
of "DEL_REASON_PEER_NOT_RESPONDING"