Wireshark mailing list archives

Re: Duplicate Packets when importing .pcap from Cisco NAM module.


From: Kevin Cullimore <kcullimo () runbox com>
Date: Tue, 10 Aug 2010 12:43:20 -0400

On 8/10/2010 11:14 AM, Sake Blok wrote:
Not sure how to do it in NAM,
It may well vary by product line (given the vendor in question, how 
could it not?), but my current understanding is that NAM requires the 
configuration of data sources, which generally are a subset of available 
mechanisms on the platforms hosting the ports to be captured from, such 
as SPAN or NDE. I went with the example I knew best.
but the principe is to only capture "incoming" (RX) packets  instead of "both" incoming and outgoing. You need to do 
this, since every packet enters *and* leaves the VLAN, thus is captured twice if you capture both. This should be 
configured at the source side of the SPAN definition...

Cheers,


Sake



On 10 aug 2010, at 16:19, Fraasch, James M. wrote:

   
How do you do that?

James Fraasch
Network Engineer


From: wireshark-users-bounces () wireshark org [mailto:wireshark-users-bounces () wireshark org] On Behalf Of Kevin 
Cullimore
Sent: Monday, August 09, 2010 5:45 PM
To: wireshark-users () wireshark org
Subject: Re: [Wireshark-users] Duplicate Packets when importing .pcap from Cisco NAM module.

On 8/9/2010 1:01 PM, Akhtar Rasool wrote:
     
Hello everyone,

I am seeing duplicate packets when importing packet captures from Cisco NAM module into Wireshark. Would appreciate 
any ideas to avoid that. Thanks.
       
If you're relying upon SPAN to monitor VLANs, you may want to ensure that you're doing so unidirectionally.
     

Regards,

Akhtar

___________________________________________________________________________
Sent via:    Wireshark-users mailing list
<wireshark-users () wireshark org>

Archives:
http://www.wireshark.org/lists/wireshark-users

Unsubscribe:
https://wireshark.org/mailman/options/wireshark-users


mailto:wireshark-users-request () wireshark org?subject=unsubscribe
       
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe
     
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
              mailto:wireshark-users-request () wireshark org?subject=unsubscribe


   

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: