Duplicate Replayed UDP Packets Seen In Wireshark - Windows 10

asked 2023-05-07 22:12:04 +0000

kula gravatar image

When trying to replay any UDP capture over some interface (for example virtual box host only interface) , with the help of Cola Packet Player (and any other actually), on Windows 10 (Enterprise) machines, I can see any replayed packet twice in the Wireshark. This is utterly confusing.

I have installed latest Wireshark and npcap version.

  • The problem persists when no other vms are connected to the virtual switch. So there's no other machines that are "reflecting" the frames.
  • The problem can be reproduced even with physical switches so not connected to specifically virtual box switch.
  • When trying to tcdump on guest vm connected to the virtual switch I can see all packets only once as expected.

I cannot upload the capture but I used snmpv3 found here https://packetlife.net/media/captures...

edit retag flag offensive close merge delete

Comments

I am facing the same problem, and all online answers say it is possible due to the loopback adapter. Have you found any solution?

kakastudy gravatar imagekakastudy ( 2024-03-03 03:56:14 +0000 )edit