This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

RTP Analysis of stream through HSRP pair + asymmetric routing = “Suspected duplicate(MAC address)"

0

Could a configuration flag be added that will tell the RTP analyzer to ignore when a source MAC address for an RTP stream changes (or to ignore Layer 2 altogether)? I have an HSRP pair with asymmetric routing behind them. Sometimes the routing will change mid RTP stream which causes the flow to egress a different HSRP router, thus a different source MAC. The RTP analysis is picking up on this, flags the packets as "Suspected Duplicate (MAC Address)", marks them as lost, and it screws up the stats.

My collector is running 1.4 and the RTP analysis looks fine. Opening the PCAP in the most recent version, 1.12.5, has this problem. I'm not sure which exact version between 1.4 and 1.12 this was introduced in.

asked 14 May '15, 14:30

KranZ's gravatar image

KranZ
6112
accept rate: 0%


One Answer:

0

The heuristics were tightened in time to better handle conflicting situations. Unfortunately your setup 'causes' such conflict to be detected. The best way to request this in a well documented Enhancement request (with sample capture file) in bugs.wireshark.org.

answered 15 May '15, 02:42

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%