wireshark,commview抓不到包的问题

wireshark,commview抓不到包的问题

wireshark,commview抓不到包的问题

在电信的业务接入过程中,使用抓包软件wireshark,抓不到包,只能抓到tcp的三次握手,后面得tcp stream 都抓不到。
使用commview ,windump结果一样。

最终解决 ,使用cmd命令 netsh int ip set chimney DISABLED


网卡类型:Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client)
操作系统:windows 2003 sp2
 

在windows2003 sp2中tcp chimney 是默认打开的,不管你用不用。

参考资料:
TOE技术以及TOE网卡的工作原理 http://hpserver.blog.51cto.com/665945/168082
还有就是从wireshark网站的一篇文档,copy如下:
Wireshark-users: Re: [Wireshark-users] Query about capturing on Broadcom BMC5708C
Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Andrew Hood <ajhood@xxxxxxxxx>
Date: Mon, 05 Jan 2009 23:33:07 +1100


Gianluca Varenni wrote:
> Does the card have TOE (TCP Offloading Engine), also known as TCP Chimney?
> If that's the case, and Chimney is enabled, you won't be able to capture the
> TCP stream because the traffic goes directly from the TCP/IP protocol driver
> to the card (thru a "chimney"), and WinPcap (the capture engine used by
> Wireshark) cannot capture such traffic.
>
> If that's the case, the only workaround is disabling Chimney on such network
> adapter.

A quick Google search found various complaints about chimney screwing up
several products, most of them referencing Broadcom NICs. They all
recommended:

netsh int ip set chimney disable

or replacing the NICs with some from another manufacturer. As "Microsoft
Windows Server 2003 Scalable Networking Pack"
http://support.microsoft.com/kb/912222 is integrated into R2, switching
NICs may no longer work.

Sure enough, Wireshark now works.

I can also add Tivoli's Framework to the list, because disabling chimney
fixed that too.

> Have a nice day

Once I had the right command to "fix" the NIC we did.

--
There's no point in being grown up if you can't be childish sometimes.
                -- Dr. Who

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值