Wireshark-users: Re: [Wireshark-users] Duplicate Packets when importing .pcap from Cisco NAM modu
From: Kevin Cullimore <kcullimo@xxxxxxxxxx>
Date: Tue, 10 Aug 2010 12:43:20 -0400
On 8/10/2010 11:14 AM, Sake Blok wrote:
Not sure how to do it in NAM,
It may well vary by product line (given the vendor in question, how could it not?), but my current understanding is that NAM requires the configuration of data sources, which generally are a subset of available mechanisms on the platforms hosting the ports to be captured from, such as SPAN or NDE. I went with the example I knew best.
but the principe is to only capture "incoming" (RX) packets  instead of "both" incoming and outgoing. You need to do this, since every packet enters *and* leaves the VLAN, thus is captured twice if you capture both. This should be configured at the source side of the SPAN definition...

Cheers,


Sake



On 10 aug 2010, at 16:19, Fraasch, James M. wrote:

How do you do that?

James Fraasch
Network Engineer


From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Kevin Cullimore
Sent: Monday, August 09, 2010 5:45 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: Re: [Wireshark-users] Duplicate Packets when importing .pcap from Cisco NAM module.

On 8/9/2010 1:01 PM, Akhtar Rasool wrote:
Hello everyone,

I am seeing duplicate packets when importing packet captures from Cisco NAM module into Wireshark. Would appreciate any ideas to avoid that. Thanks.
If you're relying upon SPAN to monitor VLANs, you may want to ensure that you're doing so unidirectionally.

Regards,

Akhtar

___________________________________________________________________________
Sent via:    Wireshark-users mailing list
<wireshark-users@xxxxxxxxxxxxx>

Archives:
http://www.wireshark.org/lists/wireshark-users

Unsubscribe:
https://wireshark.org/mailman/options/wireshark-users


mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
              mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe