Ask Your Question

BigFatCat's profile - activity

2021-07-26 07:33:06 +0000 commented question Wireshark (Win 10) No longer finds all interfaces (only USBPcap)

Hi, I am able to capture WIFI packets with AcrylicWfi. I am running Windows 21H1, Wireshark 3.4.7, NPCAP 1.50 raw wirel

2021-07-21 07:56:38 +0000 received badge  Rapid Responder (source)
2021-07-21 07:56:38 +0000 answered a question How to enable the analyze protocol with editing config file

The tshark option to enable protocol is --enable-protocol --enable-protocol mac-nr The tshark option to list all the d

2021-07-21 00:26:22 +0000 received badge  Rapid Responder (source)
2021-07-21 00:26:22 +0000 answered a question SMB client changing from one server interface to another

Hi, Is the 1G session using different IP addresses? Same IP addresses then that would be network routing or the ARP tab

2021-07-19 17:16:17 +0000 commented answer Ethers not working when using zigbee protocol

I tried the version 3.5.0rc0-2522-gf54493278f27 (v3.5.0rc0-2522-gf54493278f27) and it worked. Let me explain what I did

2021-07-19 11:13:55 +0000 received badge  Rapid Responder
2021-07-19 11:13:55 +0000 answered a question Ethers not working when using zigbee protocol

Hi, It didn't work when I tried Windows versions 3.4.7, 3.2.15, and 2.90. I discovered that it works in the developer v

2021-07-16 13:17:35 +0000 answered a question When I use the "bytes sent since last PSH flag"?

When the sender wants the receiver to send all its data in its buffer to the application, it will send a TCP PUSH. There

2021-07-16 13:17:35 +0000 received badge  Rapid Responder (source)
2021-07-09 11:24:28 +0000 received badge  Rapid Responder (source)
2021-07-09 11:24:28 +0000 answered a question Slow file transfer speeds

If you look at TCP stream one, there is packet loss from 172.31.88.172 (DUP-ACKS and SACKS from 10.88.131.18). I would

2021-07-09 10:59:37 +0000 answered a question How to get Wireshark to Display packets on the screen.

Can you share the pcap?

2021-07-09 10:59:37 +0000 received badge  Rapid Responder
2021-07-09 10:58:09 +0000 answered a question SIP/RTP Audio reproduction

You are correct, the Wireshark RTP player doesn't play GSM. The solution is extract the RTP payload and playback the au

2021-07-09 10:58:09 +0000 received badge  Rapid Responder (source)
2021-07-07 08:36:48 +0000 received badge  Rapid Responder (source)
2021-07-07 08:36:48 +0000 answered a question Spanning Tree-(for-bridges)_00 (xx.xx.xx.xx.xx.xx)

The display filter is eth.dst==xx.xx.xx.xx.xx.xx, not ether host. If you are running 3.4.x, you should be able to drag-n

2021-06-29 19:36:53 +0000 commented question UDP/RTP PL96 in a routed network

I don't have a way to test this. My thought is an udp offset filter.

2021-06-29 09:55:20 +0000 edited answer Need help to analyze a packet capture for VoIP traffic

The max delta time is the time between packets. Max delta of 55.05ms can be an issue if the receiver is expecting the s

2021-06-29 08:21:08 +0000 answered a question Need help to analyze a packet capture for VoIP traffic

Did you check the QOS markings? It should be COS 1 and be trusted. If not, then you could have large delays between RTP

2021-06-29 08:01:01 +0000 received badge  Rapid Responder (source)
2021-06-28 19:42:06 +0000 edited answer Spontaneous Internet Disconnects

Take a look at the TCP retransmissions, especially the spurious retransmissions. In your capture, the client sent a TCP

2021-06-28 18:57:50 +0000 answered a question Spontaneous Internet Disconnects

Take a look at the TCP retransmissions, especially the spurious retransmissions. In your capture, the client sent a TCP

2021-06-28 18:57:50 +0000 received badge  Rapid Responder (source)
2021-06-24 11:46:51 +0000 edited answer Is there a filter to display only broadcasts?

The display filter can be complex depending on your network because IPv6 uses multicast. Mis-configured static address c

2021-06-24 11:08:41 +0000 received badge  Rapid Responder (source)
2021-06-24 11:08:41 +0000 answered a question Is there a filter to display only broadcasts?

The display filter can be complex depending on your network. IPv6 uses multicast. Layer 3 broadcast can vary because of

2021-06-24 00:20:35 +0000 answered a question How to use Editcap on Windows?

You have to be in the "C:\Program Files\Wireshark" directory or add "C:\Program Files\Wireshark\" to your path. Persona

2021-06-24 00:20:35 +0000 received badge  Rapid Responder (source)
2021-06-23 09:08:07 +0000 commented question Rookie wireshark question

Is remote mouse installed? Remote mouse uses UDP ports 2007 and 2008.

2021-06-23 08:20:00 +0000 received badge  Rapid Responder (source)
2021-06-23 08:20:00 +0000 answered a question how to filter a udp search to show everything but your ip

I think I understand your question. You can configure Wireshark to not display the IP address columns, but the informat

2021-06-15 22:33:08 +0000 received badge  Rapid Responder
2021-06-15 22:33:08 +0000 answered a question Why are there two ip addresses in the ip.src field?

ICMP type 3 and 11 messages are sent with a brief explanation. As explain in the previous comment, packet 1 ttl was 1. T

2021-06-15 22:00:04 +0000 answered a question UDP packet matching for latency and jitter

It can be done either manually or with a script, but I do not recommend it because there are so some many "what if?" T

2021-06-15 22:00:04 +0000 received badge  Rapid Responder (source)
2021-06-12 07:48:04 +0000 answered a question Looking to track down where a network bottleneck is

The description says the readers are POE. They are most likely hardwired to a switch unless there are inline POE injecto

2021-06-12 07:48:04 +0000 received badge  Rapid Responder (source)
2021-06-12 06:30:06 +0000 received badge  Rapid Responder (source)
2021-06-12 06:30:06 +0000 answered a question Cloud Capture

Try to find out the IP address for the copier. It should be in the copier network setup page.

2021-06-10 23:19:32 +0000 edited answer How do I capture on a mirrored switch port?

Switch can be configured to mirror ingress, egress, or both directions. Copying traffic for both directions to a single

2021-06-10 09:04:01 +0000 answered a question How do I capture on a mirrored switch port?

Switch can be configured to mirror ingress, egress, or both directions. Copying traffic for both directions to a single

2021-06-10 09:04:01 +0000 received badge  Rapid Responder (source)
2021-06-10 07:33:46 +0000 answered a question Ping Traces and Wireshark captures

The contents posted are not your pings. 10.10.100.254----10.10.100.1-------------ICMP----------------70-----------------

2021-06-10 07:33:46 +0000 received badge  Rapid Responder (source)
2021-06-08 06:57:24 +0000 answered a question No traffic seen in Wireshark when I run arp -a

This is same for clients, servers, routers, etc. An ARP request is sent when there isn't an ARP entry for the destinati

2021-06-08 06:57:24 +0000 received badge  Rapid Responder (source)
2021-06-07 19:18:04 +0000 answered a question Can Wireshark help diagnose intermittent connection issues?

Are the devices you are try to troubleshoot wireless or wire line?

2021-06-07 19:18:04 +0000 received badge  Rapid Responder (source)