This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Timestamp carried by a wireshark frame is newer than frame’s timestamp which seems incorrect

0

Hello, We are monitoring NTP packets using Wireshark application (version 2.2.3). In those frames found issue that frame's timestamp is about 1600 millisecond older than the timestamp carried by that particular timestamp and this behavior seems incorrect As Wireshark in any case shouldn't be sent future timestamps. This issue is observed on Windows7 Professional while same issue is not observed on windows server 2012 R2 standard.

asked 22 Dec '16, 03:00

Deepak%20jindal's gravatar image

Deepak jindal
6112
accept rate: 0%


One Answer:

0

The timestamp in the NTP data is derived from the NTP server and the round-trip between the client and the server and the timestamp of the frame is derived by the capture mechanism on the capturing host, and as such they are from different clocks and so could be different.

answered 22 Dec '16, 05:02

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%