Ask Your Question

Revision history [back]

Why would Wireshark capture only larger sized udp packets?

The non captured packets are definitely getting to their destination and heartbeat packages with a size of 176 bytes are being captured by Wireshark. This is happening on a machine with Windows10 and on another machine with Windows Vista. I know that these machines used to capture the smaller 68 byte size packages and no capture or display filters are set. Capturing is done with promiscuous mode turned on. Could it be something that WINpcap version 4_1_3 is doing? Or Wireshark v2.6.2?

click to hide/show revision 2
None

Why would Wireshark capture only larger sized udp packets?

The non captured packets are definitely getting to their destination and heartbeat packages with a size of 176 bytes are being captured by Wireshark. This is happening on a machine with Windows10 and on another machine with Windows Vista. I know that these machines used to capture the smaller 68 byte size packages and no capture or display filters are set. Capturing is done with promiscuous mode turned on. Could it be something that WINpcap version 4_1_3 4.1.3 is doing? Or Wireshark v2.6.2?