Wireshark-users: Re: [Wireshark-users] Duplicate Packets when importing .pcap from Cisco NAM modu
On 8/10/2010 11:14 AM, Sake Blok wrote:
Not sure how to do it in NAM,
It may well vary by product line (given the vendor in question, how
could it not?), but my current understanding is that NAM requires the
configuration of data sources, which generally are a subset of available
mechanisms on the platforms hosting the ports to be captured from, such
as SPAN or NDE. I went with the example I knew best.
but the principe is to only capture "incoming" (RX) packets instead of "both" incoming and outgoing. You need to do this, since every packet enters *and* leaves the VLAN, thus is captured twice if you capture both. This should be configured at the source side of the SPAN definition...
Cheers,
Sake
On 10 aug 2010, at 16:19, Fraasch, James M. wrote:
How do you do that?
James Fraasch
Network Engineer
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Kevin Cullimore
Sent: Monday, August 09, 2010 5:45 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: Re: [Wireshark-users] Duplicate Packets when importing .pcap from Cisco NAM module.
On 8/9/2010 1:01 PM, Akhtar Rasool wrote:
Hello everyone,
I am seeing duplicate packets when importing packet captures from Cisco NAM module into Wireshark. Would appreciate any ideas to avoid that. Thanks.
If you're relying upon SPAN to monitor VLANs, you may want to ensure that you're doing so unidirectionally.
Regards,
Akhtar
___________________________________________________________________________
Sent via: Wireshark-users mailing list
<wireshark-users@xxxxxxxxxxxxx>
Archives:
http://www.wireshark.org/lists/wireshark-users
Unsubscribe:
https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
___________________________________________________________________________
Sent via: Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
___________________________________________________________________________
Sent via: Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe