[Winpcap-users] Possible TOE / Chimney issue, packets not showing up in Wireshark

Bryan Mclellan bryanm at widemile.com
Tue Dec 11 23:07:10 GMT 2007


I believe I have something similar to this: http://www.winpcap.org/pipermail/winpcap-users/2007-May/001837.html

I was first trying to troubleshoot a problem with Offline Address Books not downloading on our Exchange server. When I ran wireshark on the Exchange server and my workstation(windows xp), I saw significantly less traffic on the server.

Today I was trying to troubleshoot and LDAP problem against a DC from a Multifunction Copier. Running wireshark on the server, I was only seeing the threeway handshake and then the ldap bind request. There were no FIN or RST sequences. When I hooked up to the SPAN port I saw the entire TCP stream.

The other user in the linked message  above reported having a Broadcom BCM5708C chip. Maybe the drivers / new chimney code is causing shenanigans that aren't visible.

Wireshark: 0.99.6a
Winpcap: 4.0.1

On a Dell Poweredge 1955, Windows Server 2003 R2 Enterprise x64, with SP2.
Network is Broadcom BCM5708S NetXtreme II GigE (NDIS VBD Client) (x2, only one being used, the other is enabled without an IP)
Driver: bxnd52a.sys version 2.6.14.0 4/3/2006

In the driver properties:
Checksum Offload: None
Large Send Offload: Disable
Receive Side Scaling: Enable

In "Broadcom Advanced Control Suite 2" the Advanced tab has the same options and values.

Bryan McLellan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20071211/a3720549/attachment.htm


More information about the Winpcap-users mailing list