[Winpcap-users] acquisition position

Michel NoSpam michel.tempo at yahoo.fr
Thu Nov 5 03:23:49 PST 2009


Thanks a lot for this information, it confirms that we just realyzed: no PPP trace seen so sample point is just above .
 
I guess that there is some flow control between TCP/IP and PPP layers (We saw different behaviour with same windows stack but different modem)
Is it possible to capture such flow control with winpcap?


--- En date de : Mer 4.11.09, Gianluca Varenni <gianluca.varenni at cacetech.com> a écrit :


De: Gianluca Varenni <gianluca.varenni at cacetech.com>
Objet: Re: [Winpcap-users] acquisition position
À: winpcap-users at winpcap.org
Date: Mercredi 4 Novembre 2009, 16h47



The traffic is captured between the IP stack and PPP, although you will also see some PPP-specific packets related to the PPP negotiation).
 
Hope this helps
GV

----- Original Message ----- 
From: Michel NoSpam 
To: winpcap-users at winpcap.org 
Sent: Wednesday, November 04, 2009 12:25 AM
Subject: Re: [Winpcap-users] acquisition position





Adapter for generic dialup and VPN capture

--- En date de : Mar 3.11.09, Gianluca Varenni <gianluca.varenni at cacetech.com> a écrit :


De: Gianluca Varenni <gianluca.varenni at cacetech.com>
Objet: Re: [Winpcap-users] acquisition position
À: winpcap-users at winpcap.org
Date: Mardi 3 Novembre 2009, 17h39



What's the name and description of the adapter that you are capturing from in wireshark?
 
 

----- Original Message ----- 
From: Michel NoSpam 
To: winpcap-users at winpcap.org 
Sent: Tuesday, November 03, 2009 7:44 AM
Subject: Re: [Winpcap-users] acquisition position






I am using Wireshark on Windows XP professionnal SP2

--- En date de : Mar 3.11.09, Gianluca Varenni <gianluca.varenni at cacetech.com> a écrit :


De: Gianluca Varenni <gianluca.varenni at cacetech.com>
Objet: Re: [Winpcap-users] acquisition position
À: winpcap-users at winpcap.org
Date: Mardi 3 Novembre 2009, 16h35





What is the name and description of the adapter you are capturing from? Which operating system?
 
Have a nice day
GV

----- Original Message ----- 
From: Michel NoSpam 
To: winpcap-users at winpcap.org 
Sent: Tuesday, November 03, 2009 12:59 AM
Subject: [Winpcap-users] acquisition position






Hello, 

 
I would to know a which level Wireshark/Winpcap samples the IP packets.
I use a mobile phone as a modem (DUN). A flow control permits to adjust the data flow from the PC to the modem.

We have a downlink and a uplink data flow.
Because of this flow control, we can see that the downlink TCP data are not acknowledge immediately.

I would like to know where wireshark samples the data?
When the data leave the ipstack or when the data leave the PC?
Can I configure wireshark/winpcap to sample the packet a layer 3?
(I am affraid it could have some important delay between layer3 -> layer 2 -> layer 1)

(stack ip -> PPP -> USB -> modem) 


Thanks a lot. 
Michel




_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users

-----La pièce jointe associée suit-----


_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users





_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users

-----La pièce jointe associée suit-----


_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users





_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users

-----La pièce jointe associée suit-----


_______________________________________________
Winpcap-users mailing list
Winpcap-users at winpcap.org
https://www.winpcap.org/mailman/listinfo/winpcap-users



      
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20091105/6a42397b/attachment.htm 


More information about the Winpcap-users mailing list