Could a configuration flag be added that will tell the RTP analyzer to ignore when a source MAC address for an RTP stream changes (or to ignore Layer 2 altogether)? I have an HSRP pair with asymmetric routing behind them. Sometimes the routing will change mid RTP stream which causes the flow to egress a different HSRP router, thus a different source MAC. The RTP analysis is picking up on this, flags the packets as "Suspected Duplicate (MAC Address)", marks them as lost, and it screws up the stats.

My collector is running 1.4 and the RTP analysis looks fine. Opening the PCAP in the most recent version, 1.12.5, has this problem. I'm not sure which exact version between 1.4 and 1.12 this was introduced in.

The heuristics were tightened in time to better handle conflicting situations. Unfortunately your setup 'causes' such conflict to be detected. The best way to request this in a well documented Enhancement request (with sample capture file) in

question asked: 14 May '15, 14:30

last updated: 15 May '15, 02:42

