[Winpcap-users] Timestamp reliability
Claudio Raiti
claudio.raiti at hotmail.it
Fri Dec 7 19:33:37 GMT 2007
Hi,
i would like to know how reliable NPF timestamps are. When i capture the traffic i created with an application using PACKET.DLL between two notebooks, i note that they are very strange. I've tried to capture with Wireshark too, but the results are the same. If i measure interspace time between two consecutive frames, i see very often that the timestamps indicate a too short interval. For example, wireshark gives me these two lines:
No. Time Source Destination Protocol Info
...
9 0.000911 xxxx ...
10 0.000912 xxx ...
...
How possible that a frame is arrived after one usec? The traffic i create is done with a nominal interframe time of 0.01 ms (that should be over the effective router capacity).
I'm using a 802.11N router with PCMCIA wireless card with atheros chipset AR5008 and Windows XP/Vista on the two notebooks.
Who can help me?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20071207/b62939e1/attachment.htm
More information about the Winpcap-users
mailing list