Hello users,

I could use some help in troubleshooting  Rpcapd.
I have been using remote daemon on and off for years using both Wireshark and 
SharpPcap.
I found rpcapd so beneficial, I submitted the C# code for the SharpPcap team to 
access the rpcapd.

I have a problem that affects Wireshark and SharpPcap the same. The system 
works fine, I collect and decode lots of beneficial data for my company. The 
issue is that the connection just stops, say in a day. It's hard to determine 
when, because there is no actual error generated when it drops. I find out by 
activating a test client to transmit data,  but no packets come through either 
wireshark or SharpPcap.

My setup:

-          Laptop Dell Latitude E6510, 3.92GB of RAM, Win7-64 bit running 
WinPcap 4.1.2.

-          Dell T3500, 12Gb of RAM, Win7-64, running either Wireshark Version 
1.2.9 or a C# app (using SharpPcap lib) or both.

-          For troubleshooting I usually have both C# app and Wireshark running 
together using the same rcap filter.

-          rcap filters are typically "host 10.x.x.x."

-          I would like to get to the point of having 8-12 concurrent sessions 
running for a month without failing.

In the morning, I typically close Wireshark and the C# app. Wireshark generates 
an error 10054 (see attached). I believe it's because the TCP connect was RST 
by the laptop when wireshark attempts to close the connection gracefully.

BTW: I have a WS trace of the two computers showing when Wireshark received the 
RST.
Also. I can simply restart a wireshark capture or  the C# app and data will 
start following again. Rpcapd does not need to be restarted. The laptop does 
not need to pinged 1st or logged into.

I hope this was no too much on my first post.
Best regards.

_______________________________________________
Winpcap-users mailing list
[email protected]
https://www.winpcap.org/mailman/listinfo/winpcap-users

Reply via email to