Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Duplicate Replayed UDP Packets Seen In Wireshark - Windows 10

When trying to replay any UDP capture over some interface (for example virtual box host only interface) , with the help of Cola Packet Player (and any other actually), on Windows 10 (Enterprise) machines, I can see any replayed packet twice in the Wireshark. This is utterly confusing.

I have installed latest Wireshark and npcap version.

  • The problem persists when no other vms are connected to the virtual switch. So there's no other machines that are "reflecting" the frames.
  • The problem can be reproduced even with physical switches so not connected to specifically virtual box switch.
  • When trying to tcdump on guest vm connected to the virtual switch I can see all packets only once as expected.

I cannot upload the capture but I used snmpv3 found here https://packetlife.net/media/captures/SNMPv3.cap