Hello users, I could use some help in troubleshooting Rpcapd. I have been using remote daemon on and off for years using both Wireshark and SharpPcap. I found rpcapd so beneficial, I submitted the C# code for the SharpPcap team to access the rpcapd.
I have a problem that affects Wireshark and SharpPcap the same. The system works fine, I collect and decode lots of beneficial data for my company. The issue is that the connection just stops, say in a day. It's hard to determine when, because there is no actual error generated when it drops. I find out by activating a test client to transmit data, but no packets come through either wireshark or SharpPcap. My setup: - Laptop Dell Latitude E6510, 3.92GB of RAM, Win7-64 bit running WinPcap 4.1.2. - Dell T3500, 12Gb of RAM, Win7-64, running either Wireshark Version 1.2.9 or a C# app (using SharpPcap lib) or both. - For troubleshooting I usually have both C# app and Wireshark running together using the same rcap filter. - rcap filters are typically "host 10.x.x.x." - I would like to get to the point of having 8-12 concurrent sessions running for a month without failing. In the morning, I typically close Wireshark and the C# app. Wireshark generates an error 10054 (see attached). I believe it's because the TCP connect was RST by the laptop when wireshark attempts to close the connection gracefully. BTW: I have a WS trace of the two computers showing when Wireshark received the RST. Also. I can simply restart a wireshark capture or the C# app and data will start following again. Rpcapd does not need to be restarted. The laptop does not need to pinged 1st or logged into. I hope this was no too much on my first post. Best regards.
_______________________________________________ Winpcap-users mailing list [email protected] https://www.winpcap.org/mailman/listinfo/winpcap-users
