Re: Does Ethereal lose packets?

From: NeoSadist (
Date: 02/02/04

Date: Sun, 01 Feb 2004 23:09:12 -0700

Justin Gombos wrote:

> I ran nmap with a Windows XP box as a target, while using ethereal to
> sniff the traffic. It found a few open ports, one of which was 445
> (microsoft-ds). I used this ethereal filter on a large dump of
> packets:
> tcp.flags eq 0x0012 && tcp.port == 445
> No packets came from port 445 of the target host.
> Then I repeated the process, and there was a SYN ACK packet the second
> time. Why would this happen? Are the packets moving too fast for
> ethereal to grab them all?

Maybe you're trying to catch packets in permiscuous mode, or not in
permiscuous mode. Please try using permiscuous mode and tell us if it
still has this problem.

