[Winpcap-users] Bogus IP Header

Gordon Graham gcgraham33 at hotmail.com
Sat Jun 18 06:05:42 GMT 2005


I just installed Ethereal and WinPcap (ver 3.0) today and am having trouble 
capturing packets properly. I am able to capture a series of packets but 
almost every one says "Bogus IP length 0 ..." or Bogus IP header ...".

In the packet details area of Ethereal the Frame information says something 
like (1514 bytes on wire, 28 bytes captured). Different frames have a 
different number of "bytes on the wire" but all seem to say 28 bytes 
captured. I've tried promiscuous mode and not promiscuous mode with the same 
results. Otherwise, I'm using all the default values.

I'm running on a Windows ME laptop using the integrated 8255 fast ethernet 
controller and I'm connected to a NetGear router (home setup). I run the 
McAfee personal firewall but turned it off. I also have a docking station 
with a different Ethernet interface. I tried capturing from that interface 
with the same results.

I posted this question on the Ethereal list. They suggested that it might be 
an issue with WinPcap and suggested I try here.

Does anyone have an idea about what I might be doing wrong and how I can 
correct things?

Any help would be greatly appreciated!

Thanks!
Gordon





More information about the Winpcap-users mailing list