Ask Your Question

Revision history [back]

Double Profinet packets logged by Wireshark

I am analyzing traffic of my Profinet network, made of:

  • S7-1200 CPU;

  • Slave device with OS WES7;

  • ETH switch.

My Slave device, from which I run Wireshark v.3.2.1, has 5 ETH ports but the analysis via Wireshark is done on the correct and only active port, which connects the Slave device to the ETH switch.

Why in my Wireshark logs I see that outbound PNIO packets are logged twice, while inbound packets are logged once?

If I log the inbound and outbound traffic of the ETH port to which the Slave device is connected using a switch with a mirrored port and Wireshark v.3.2.1 installed on an external PC, Wireshark logs show that the packets are actually sent only once from the device (not twice as the wireshark logs collected from the device itself had reported).