Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Why is wireshark showing capturing frame size 16523 while network adapter is configured to 1514 bytes?

Frame 7739: 16523 bytes on wire (132184 bits), 16523 bytes captured (132184 bits) on interface \Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}, id 0 Section number: 1 Interface id: 0 (\Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}) Encapsulation type: Ethernet (1) Arrival Time: Apr 7, 2023 13:24:20.479086000 Central Europe Daylight Time [Time shift for this packet: 0.000000000 seconds] Epoch Time: 1680866660.479086000 seconds [Time delta from previous captured frame: 0.000123000 seconds] [Time delta from previous displayed frame: 0.000123000 seconds] [Time since reference or first frame: 26.115296000 seconds] Frame Number: 7739 Frame Length: 16523 bytes (132184 bits) Capture Length: 16523 bytes (132184 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:tls] [Coloring Rule Name: TCP] [Coloring Rule String: tcp] Ethernet II, Src: VMware_xx:yy:d7 (00:yy:zz), Dst: All-HSRP-routers_35 (00:00:xx:07:yy:35) Internet Protocol Version 4, Src: ..., Dst: +.+.+.+.+ Transmission Control Protocol, Src Port: 52366, Dst Port: 16806, Seq: 20675212, Ack: 279996, Len: 16469 Transport Layer Security

click to hide/show revision 2
None

Why is wireshark showing capturing frame size 16523 while network adapter is configured to 1514 bytes?

Frame 7739: 16523 **16523 bytes on wire wire** (132184 bits), 16523 bytes captured **16523 bytes captured** (132184 bits) on interface \Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}, id 0 Section number: 1 Interface id: 0 (\Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}) Encapsulation type: Ethernet (1) Arrival Time: Apr 7, 2023 13:24:20.479086000 Central Europe Daylight Time [Time shift for this packet: 0.000000000 seconds] Epoch Time: 1680866660.479086000 seconds [Time delta from previous captured frame: 0.000123000 seconds] [Time delta from previous displayed frame: 0.000123000 seconds] [Time since reference or first frame: 26.115296000 seconds] Frame Number: 7739 Frame Length: 16523 bytes (132184 bits) Capture Length: 16523 bytes (132184 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:tls] [Coloring Rule Name: TCP] [Coloring Rule String: tcp] Ethernet II, Src: VMware_xx:yy:d7 (00:yy:zz), Dst: All-HSRP-routers_35 (00:00:xx:07:yy:35) Internet Protocol Version 4, Src: ..., *.*.*.*, Dst: +.+.+.+.+ Transmission Control Protocol, Src Port: 52366, Dst Port: 16806, Seq: 20675212, Ack: 279996, Len: 16469 Transport Layer SecuritySecurity

click to hide/show revision 3
None

Why is wireshark showing capturing frame size 16523 while network adapter is configured to 1514 bytes?

Frame 7739: **16523 16523 bytes on wire** wire (132184 bits), **16523 16523 bytes captured** captured (132184 bits) on interface \Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}, id 0 Section number: 1 Interface id: 0 (\Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}) Encapsulation type: Ethernet (1) Arrival Time: Apr 7, 2023 13:24:20.479086000 Central Europe Daylight Time [Time shift for this packet: 0.000000000 seconds] Epoch Time: 1680866660.479086000 seconds [Time delta from previous captured frame: 0.000123000 seconds] [Time delta from previous displayed frame: 0.000123000 seconds] [Time since reference or first frame: 26.115296000 seconds] Frame Number: 7739 Frame Length: 16523 bytes (132184 bits) Capture Length: 16523 bytes (132184 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:tls] [Coloring Rule Name: TCP] [Coloring Rule String: tcp] Ethernet II, Src: VMware_xx:yy:d7 (00:yy:zz), Dst: All-HSRP-routers_35 (00:00:xx:07:yy:35) Internet Protocol Version 4, Src: *.*.*.*, ..., Dst: +.+.+.+.+ Transmission Control Protocol, Src Port: 52366, Dst Port: 16806, Seq: 20675212, Ack: 279996, Len: 16469 Transport Layer Security Security

click to hide/show revision 4
None

Why is wireshark showing capturing frame size 16523 while network adapter is configured to 1514 bytes?

Example:

Frame 7739: 16523 **16523 bytes on wire wire** (132184 bits), 16523 bytes captured **16523 bytes captured** (132184 bits) on interface \Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8}, id 0
     Section number: 1
     Interface id: 0 (\Device\NPF_{D50C0374-3F2F-4B7F-A765-2E3C7ABEE1A8})
     Encapsulation type: Ethernet (1)
     Arrival Time: Apr  7, 2023 13:24:20.479086000 Central Europe Daylight Time
     [Time shift for this packet: 0.000000000 seconds]
     Epoch Time: 1680866660.479086000 seconds
     [Time delta from previous captured frame: 0.000123000 seconds]
     [Time delta from previous displayed frame: 0.000123000 seconds]
     [Time since reference or first frame: 26.115296000 seconds]
     Frame Number: 7739
     Frame Length: 16523 bytes (132184 bits)
     Capture Length: 16523 bytes (132184 bits)
     [Frame is marked: False]
     [Frame is ignored: False]
     [Protocols in frame: eth:ethertype:ip:tcp:tls]
     [Coloring Rule Name: TCP]
     [Coloring Rule String: tcp]
 Ethernet II, Src: VMware_xx:yy:d7 (00:yy:zz), Dst: All-HSRP-routers_35 (00:00:xx:07:yy:35)
 Internet Protocol Version 4, Src: ..., *.*.*.*, Dst: +.+.+.+.+
 Transmission Control Protocol, Src Port: 52366, Dst Port: 16806, Seq: 20675212, Ack: 279996, Len: 16469
 Transport Layer Security

Security