I'm currently facing issue when tryin to capture network communications from Win 7 X64 stations. When I start a capture from a client, in the capture I most of the time I don't see packets sent by the client.
Strangely it's quite random. Sometines I see packets from the client at the begining of the communication but after a short while I see only packets from server.
Do you have any idea causing this issue. This is blocking my network analyse so I need to solve it.
Is this related to offload / chimney behavior?
Thanks for your help
asked 15 Jan '14, 06:40
edited 10 Feb '14, 05:55
That's usually a sign for TCP offloading into the NIC driver. You will see the 3-way handshake and then nothing, as the rest of the communication is handled by the NIC itself and that traffic is invisible to Wireshark (due to the way the capturing library inserts itself into the kernel).
BTW: Apparently you already knew that, as you chose the right tags (offload and chimney) ;-))
There are other reasons, like 'strange network drivers', security software, etc.
See also other, similar, questions with the tags 'outgoing' or 'outbound'
BTW: I just updated the tags of some of those questions, as this specific problem arised a few times lately.
answered 15 Jan '14, 07:03
Kurt Knochner ♦
edited 15 Jan '14, 07:17