1 | initial version |
Sounds like your responses are send in a way that does not match you ethernet address. So when wireshark runs you get the data because you switch to promicious mode.
I think it should show in the packet capture if you look at the thernet addresses very carefully.