Wireshark-users: Re: [Wireshark-users] Wireshark-users Digest, Vol 4, Issue 35
From: "Sean Baker" <sbaker48@xxxxxxxxx>
Date: Thu, 28 Sep 2006 11:36:49 -0400
On 9/28/06, "ronnie sahlberg" <ronniesahlberg@xxxxxxxxx> wrote:

It looks like you capture all outgoing packets twice some 30us apart.

Is this captured on windows hosts? do you use something like BlackIce on
that windows host?

There is some interaction between tools such as BlackIce and the capture
process on windows that sometimes lead to the outgoing packets being
captured twice in exactly this manner.

Both hosts were running WinXP. There is a AES NDIS Filter Driver that provides encryption for the mesh network, maybe that is what is causing the problem. I'm not sure what else it could be.

Is there a filter that I can use to block out the duplicate packets?

Thanks,
--Sean