[Winpcap-users] Using WinPcap "breaks" TCP

1603 at gmx.de 1603 at gmx.de
Thu Jul 12 12:41:39 GMT 2007


Hello Marc,


> Googling, I just found that there seems to be problem with using Winpcap and
> Kerio Firewall [...]

I can certainly vouch for that, this very problem has been bugging me for
quite some time. It has even gotten worse over the releases:

On machines running Kerio (v2.1.5, I believe) I can't upgrade WinPCap
to anything higher than v3.1beta4. Even switching to beta5 causes the
system to freeze when starting a trace in Ethereal, sometimes the
first time, usually the second one (start-stop-start-freeze.)

Unfortunatly I can't abandon Kerio either because inspite of intensive
searching I have yet to find an adequate replacement. I've looked at
what must be close to 50 different firewalls but was unable to find
anything suitable. If you discover something interesting, I'd be
grateful for a hint.


The Kerio-broken-protocol-issue isn't necessarily due to WinPCap at
all: Some of my machines tend to have problems establishing an
outgoing VPN connection via PPTP. When looking into the wire I can
also see that the handshake is performed, but no data transmitted
afterwards. Often modifying the load time for the Kerio driver
fwdrv.sys from "automatic" to "manual" (or vice versa, different
machines appear to like a different setting) helps and the problem
vanishes, if only to resurface again some months later.



-- 
Mit freundlichen Grüßen
1603 at gmx.de
mailto:1603 at gmx.de





More information about the Winpcap-users mailing list