cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
331
Views
4
Helpful
5
Replies

9800WLC Wireshark Trace contains duplicate packets

Gehrig_W
Level 1
Level 1

Hello Cisco WLAN experts,

I tryin to understand packet flow between our 9800-80-WLC and a 9800-L-C-Guest WLC and started a simple paket capture like the following one on one of the interfaces of a Port channel on the 9800-L-C Version 17.3.6

Gehrig_W_0-1758104528163.png

To my surprise, the resulting Wireshark paket capture shows duplicate data packets:

Gehrig_W_1-1758104656660.png

When I see ARP-PAckets, the seocnd packets diifers slightly in size and is filled up with some Bytes of "00".

When it comes to real data traffic packets, Whireshark is wrongly interpreting these duplicates as Retransmits.

Who has a good idea or explantion for this duplication ?

Is it due to a wrong network design ?

Both WLCs are connected via Trunk lines to a central router and the captured interface is from a Trunk interface towards  Internet.

Thank You for any explanation.

Kind regards

Wini

 

 

 

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

The duplicates are quite simply because you are capturing on physical interface(s) and control plane.

Any packet which is sent/received to/from control plane (processor) like ARP will appear twice.  The MAC header will only appear on the physical interface, the control plane packet has a virtual header.  So this behaviour is 100% expected.

View solution in original post

5 Replies 5

I also notice that' 

It duplicate but if I am right and you take deep look you will see one is send with vlan tag and other as native.

MHM

Hello MHM,

the difference in VLAN is visible on the newer 9800-80 version 17.9.5. Obviously the filter has been improved here:

Gehrig_W_0-1758114149640.png

Here I can choose a uniqe MAC-Address of  WLAN-Client instead of a whole IP-subnet.

The inner filter MAC is not visible in 17.3.6:

Gehrig_W_1-1758114322034.png

So it looks like a bug to me.

Kind regards

Wini

 

 

 

 

 

balaji.bandi
Hall of Fame
Hall of Fame

is the source IP from client IP address ?

how many you see these kind of Duplicate, and compare what clients they are ?

Go deeper extract one of them see what is wrong ?

example :

https://mrncciew.com/2012/12/27/understanding-dhcp

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Rich R
VIP
VIP

The duplicates are quite simply because you are capturing on physical interface(s) and control plane.

Any packet which is sent/received to/from control plane (processor) like ARP will appear twice.  The MAC header will only appear on the physical interface, the control plane packet has a virtual header.  So this behaviour is 100% expected.

Gehrig_W
Level 1
Level 1

Hello Rich,

thank You very much for this important information. It is working like this on the newer 17.9.5-Code.

In the elder 17.6.3-version I see only 2 packets in a 10 Seconds interval, when i uncheck Monitor Control Plane

on our Guest-WLC covering several thousands of users:

Gehrig_W_1-1758693998171.png

 

Gehrig_W_0-1758693962606.png

In contrast to that, when I activate Monitor Control Plane, I see apparently the whole traffic but with duplicates for ARP and DHCP:

Gehrig_W_3-1758694333217.png

 

Gehrig_W_2-1758694275217.png

It looks like a bug in this SW-version.

I have planned a SW-Upgrade for this box  and hope to solve this cosmetic problem also.

Therefore I accept Your  reply as a solution and say

Thank You very much for Your professional help.

Greetings from Frankonia.

Wini

 

Review Cisco Networking for a $25 gift card