[Winpcap-users] Timestamp reliability

Claudio Raiti claudio.raiti at hotmail.it
Fri Dec 7 19:33:37 GMT 2007


Hi,
i would like to know how reliable NPF timestamps are. When i capture the traffic i created with an application using PACKET.DLL between two notebooks, i note that they are very strange. I've tried to capture with Wireshark too, but the results are the same. If i measure interspace time between two consecutive frames, i see very often that the timestamps indicate a too short interval. For example, wireshark gives me these two lines:

No.    Time    Source    Destination    Protocol    Info

...
9    0.000911    xxxx    ...
10    0.000912    xxx    ...
...

How possible that a frame is arrived after one usec? The traffic i create is done with a nominal interframe time of 0.01 ms (that should be over the effective router capacity).

I'm using a 802.11N router with PCMCIA wireless card with atheros chipset AR5008 and Windows XP/Vista on the two notebooks.

Who can help me?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/winpcap-users/attachments/20071207/b62939e1/attachment.htm


More information about the Winpcap-users mailing list