Wireshark-users: [Wireshark-users] editcap and duplicate removal
From: Phillip Heller <pheller@xxxxxx>
Date: Fri, 19 Dec 2008 18:59:14 +0100
So I have a vlan spanned on a Cisco 3560, and did not specify rx or tx, so it therefore defaults to snooping both, resulting in duplicate packets.

I ran editcap -d against the capture file, which did remove the duplicates -- but only in one direction!

This specific capture was of a SIP call, and when I open the resultant file, I still see that the SIP and RTP data from my media gateway towards provider is duplicated.

It's not a giant deal, but it makes the RTP media stream playback pretty much suck.

Anyone else run into this?

--phil