Wireshark mailing list archives

Re: capture issue with passive network tap - ETHERNET FRAME CHECK SEQUENCE INCORRECT - now with attachments


From: Jaap Keuter <jaap.keuter () xs4all nl>
Date: Thu, 9 Feb 2017 21:39:27 +0100

Hi,

Try using this display filter:  frame.interface_id == 1
Then you’ll see all the frames with checksum errors. Now change it to ‘0’. No errors to be seen. 
So, these USB-Ethernet devices perform differently, whereby the the one on interface 1 is questionable.

Thanks,
Jaap


On 9 Feb 2017, at 06:58, Dennis Schneck <dennisschneck () web de> wrote:

 
Hello,
i tryed to capture with a passive network tap
( wiring like: http://www.it-dienstleistungen.de/wp-content/uploads/passive_fig_2-300x270.gif 
<http://www.it-dienstleistungen.de/wp-content/uploads/passive_fig_2-300x270.gif> )
a host with 100MB/FULL, use two diffrent usb-ethernet cards ( with 100MB/FULL too, checked with ethtool )
on "tap a" and "tab b".
See in wireshark "Info column": ETHERNET FRAME CHECK SEQUENCE INCORRECT
Is there a setup for the usb-ethernet cards
to get it work fine ? What did I wrong ?
 
Wireshark is running on a Linux System
 
http:  ETHERNET FRAME CHECK SEQUENCE INCORRECT
icmp:  (no response found!) ETHERNET FRAME CHECK SEQUENCE INCORRECT

Thanks
Dennis
 
 
<01_interfaces.png><02_wireshark_icmp_displayfilter.png><03_wireshark_http_displayfilter.png><capture.pcapng>___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request () wireshark org?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: