2 ICMP Echo Request packets for every 1 ICMP Reply seen in Wireshark

1,509 views
Skip to first unread message

seanp....@gmail.com

unread,
Feb 8, 2017, 10:43:29 PM2/8/17
to ostinato
Hi,
I was capturing ICMP traffic from Ostinato and noticed Wireshark showed 2 ICMP Echo requests packets for every frame sent, and only 1 reply.
I've done a visual side-by-side comparison of both Echo Request packets, and can't see a difference except for the Time in Wireshark.

Is Ostinato sending 2 frames or am I interpreting something incorrectly?

I've attached a screenshot with the 2 requests/1 reply of the wireshark capture, but can attach a pcap if that will help.

Thank you,
Sean
Ostinato - 2 ICMP for every 1 reply.JPG

Srivats P

unread,
Feb 9, 2017, 9:57:51 AM2/9/17
to seanp....@gmail.com, ostinato
Sean,

What platform are you and what interface is this capture on?

Could you describe your topology a bit more and let us know from where
you are sending ICMP echo?

Save and attach your ICMP stream in Ostinato here, so that I can take
a look at it.

Srivats
> --
> Get Ostinato News and Updates on Twitter - Follow @ostinato
> (http://twitter.com/ostinato)
> ---
> You received this message because you are subscribed to the Google Groups
> "ostinato" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ostinato+u...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.



--
http://ostinato.org/
@ostinato

Sean Bennett

unread,
Feb 16, 2017, 12:22:31 AM2/16/17
to Srivats P, ostinato
Hi Srivats,

Currently I'm using the Windows binary of Ostinato v0.8 on a Windows 2012R2 Virtual Machine.

The VM is connected to the LAN side of a Gateway with subnet 10.1.1.0/24.
I'm attempting to send the ICMP request through the Gateway to the WAN subnet (90.90.90.0/24).

If I ping using the Win 2012R2 or another host on the 10.1.1.0 subnet, it only shows 1 ICMP request.
As soon as I use Ostinato with the attached ICMP stream, that's where I notice 2 ICMP requests.
The first one says "no response found" in Wireshark,and the second, which is a couple of milliseconds difference, has an ICMP reply.

I've googled the issue, and am unable to find anyone with a similar problem.  I can't tell if this is an Ostinato issue,
or if Wireshark is reporting it incorrectly.

Thank you,
Sean

2xICMP_stream.ostm

Carlos G Mendioroz

unread,
Feb 16, 2017, 5:02:25 AM2/16/17
to Sean Bennett, Srivats P, ostinato
Sean,
if your stream generates two requests, it might be that the destination
has some form of rate limit and only answers, say, one every 200ms.

When you generate requests using windows ping, you only generate 1 every
second or so. Wireshark just does its best to match what it sees on the
link.

HTH,
-Carlos

Sean Bennett @ 15/02/2017 13:32 -0300 dixit:
> Hi Srivats,
>
> Currently I'm using the Windows binary of Ostinato v0.8 on a Windows
> 2012R2 Virtual Machine.
>
> The VM is connected to the LAN side of a Gateway with subnet 10.1.1.0/24
> <http://10.1.1.0/24>.
> I'm attempting to send the ICMP request through the Gateway to the WAN
> subnet (90.90.90.0/24 <http://90.90.90.0/24>).
> > email to ostinato+u...@googlegroups.com
> <mailto:ostinato%2Bunsu...@googlegroups.com>.
> > For more options, visit https://groups.google.com/d/optout <https://groups.google.com/d/optout>.
>
>
>
> --
> http://ostinato.org/
> @ostinato
>
>
> --
> Get Ostinato News and Updates on Twitter - Follow @ostinato
> (http://twitter.com/ostinato)
> ---
> You received this message because you are subscribed to the Google
> Groups "ostinato" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to ostinato+u...@googlegroups.com
> <mailto:ostinato+u...@googlegroups.com>.
> For more options, visit https://groups.google.com/d/optout.

--
Carlos G Mendioroz <tr...@huapi.ba.ar> LW7 EQI Argentina

Srivats P

unread,
Feb 16, 2017, 11:17:26 AM2/16/17
to Carlos G Mendioroz, Sean Bennett, ostinato
The stream looks alright to me and is sending only 1 packet and not
looping either. When I open the stream on my Windows XP box, it just
sends one packet.

When you transit this stream in Ostinato, how much does "Frames sent"
in the stats window for that port increase by?
What is the vNIC that you are using?
Is Wireshark capture running on the same Windows 2012 VM or on a different box?

Srivats
--
http://ostinato.org/
@ostinato

Carlos G Mendioroz

unread,
Feb 17, 2017, 7:42:07 AM2/17/17
to Sean Bennett, Srivats P, ostinato
Hmm,
do you have "Promiscuous mode" enabled in the vswitch ?
Is this an ESXi or Workstation? (or Fusion?)
Virtual switches are not really switches (well, no transparent switches
at least) and may be it is reflecting the tx frame and wireshark sees it
twice.


Sean Bennett @ 17/02/2017 09:34 -0300 dixit:
> Hi Srivats,
>
> The "Frames sent" only increases by 1.
> The VM is run through VMWare and the vNIC adaptor type is E1000E.
> Inside the VM the OS thinks it is a "Intel(R) 82574L Gigabit Network
> Connection".
>
> The Wireshark capture is running on the same Windows 2012VM.
>
> Sean
> >> subnet (90.90.90.0/24 <http://90.90.90.0/24> <http://90.90.90.0/24>).
> >>
> >> If I ping using the Win 2012R2 or another host on the 10.1.1.0
> subnet,
> >> it only shows 1 ICMP request.
> >> As soon as I use Ostinato with the attached ICMP stream, that's
> where I
> >> notice 2 ICMP requests.
> >> The first one says "no response found" in Wireshark,and the second,
> >> which is a couple of milliseconds difference, has an ICMP reply.
> >>
> >> I've googled the issue, and am unable to find anyone with a similar
> >> problem. I can't tell if this is an Ostinato issue,
> >> or if Wireshark is reporting it incorrectly.
> >>
> >> Thank you,
> >> Sean
> >>
> >> On Thu, Feb 9, 2017 at 9:57 AM, Srivats P <psta...@gmail.com
> <mailto:psta...@gmail.com>
> >> <mailto:psta...@gmail.com <mailto:psta...@gmail.com>>> wrote:
> >>
> >> Sean,
> >>
> >> What platform are you and what interface is this capture on?
> >>
> >> Could you describe your topology a bit more and let us know
> from where
> >> you are sending ICMP echo?
> >>
> >> Save and attach your ICMP stream in Ostinato here, so that I
> can take
> >> a look at it.
> >>
> >> Srivats
> >>
> >> On Thu, Feb 9, 2017 at 1:16 AM, <seanp....@gmail.com
> <mailto:seanp....@gmail.com>
> >> <mailto:seanp....@gmail.com
> >> <mailto:ostinato%2Bunsu...@googlegroups.com
> <mailto:ostinato%252Buns...@googlegroups.com>>.
> >> > For more options, visit https://groups.google.com/d/optout
> <https://groups.google.com/d/optout>
> <https://groups.google.com/d/optout
> <https://groups.google.com/d/optout>>.
> >>
> >>
> >>
> >> --
> >> http://ostinato.org/
> >> @ostinato
> >>
> >>
> >> --
> >> Get Ostinato News and Updates on Twitter - Follow @ostinato
> >> (http://twitter.com/ostinato)
> >> ---
> >> You received this message because you are subscribed to the Google
> >> Groups "ostinato" group.
> >> To unsubscribe from this group and stop receiving emails from it,
> send
> >> an email to ostinato+u...@googlegroups.com
> <mailto:ostinato%2Bunsu...@googlegroups.com>
> >> <mailto:ostinato+u...@googlegroups.com
> > Carlos G Mendioroz <tr...@huapi.ba.ar <mailto:tr...@huapi.ba.ar>>

Sean Bennett

unread,
Feb 17, 2017, 9:59:08 AM2/17/17
to Srivats P, Carlos G Mendioroz, ostinato
Hi Srivats,

The "Frames sent" only increases by 1.
The VM is run through VMWare and the vNIC adaptor type is E1000E.
Inside the VM the OS thinks it is a "Intel(R) 82574L Gigabit Network Connection".

The Wireshark capture is running on the same Windows 2012VM.

Sean

>>     <mailto:seanp.bennett@gmail.com>> wrote:
>>     > Hi,
>>     > I was capturing ICMP traffic from Ostinato and noticed Wireshark
>>     showed 2
>>     > ICMP Echo requests packets for every frame sent, and only 1 reply.
>>     > I've done a visual side-by-side comparison of both Echo Request
>>     packets, and
>>     > can't see a difference except for the Time in Wireshark.
>>     >
>>     > Is Ostinato sending 2 frames or am I interpreting something
>>     incorrectly?
>>     >
>>     > I've attached a screenshot with the 2 requests/1 reply of the
>>     wireshark
>>     > capture, but can attach a pcap if that will help.
>>     >
>>     > Thank you,
>>     > Sean
>>     >
>>     > --
>>     > Get Ostinato News and Updates on Twitter - Follow @ostinato
>>     > (http://twitter.com/ostinato)
>>     > ---
>>     > You received this message because you are subscribed to the Google Groups
>>     > "ostinato" group.
>>     > To unsubscribe from this group and stop receiving emails from it, send an

>>     <mailto:ostinato%2Bunsu...@googlegroups.com>.
>>     > For more options, visit https://groups.google.com/d/optout <https://groups.google.com/d/optout>.
>>
>>
>>
>>     --
>>     http://ostinato.org/
>>     @ostinato
>>
>>
>> --
>> Get Ostinato News and Updates on Twitter - Follow @ostinato
>> (http://twitter.com/ostinato)
>> ---
>> You received this message because you are subscribed to the Google
>> Groups "ostinato" group.
>> To unsubscribe from this group and stop receiving emails from it, send

>> For more options, visit https://groups.google.com/d/optout.
>
> --
> Carlos G Mendioroz  <tr...@huapi.ba.ar>  LW7 EQI  Argentina



--
http://ostinato.org/
@ostinato

Sean Bennett

unread,
Feb 17, 2017, 9:59:37 AM2/17/17
to Carlos G Mendioroz, ostinato, Srivats P
Hi Carlos,

That's a good idea. I do have promiscuous mode turned on.
The set up is ESXi.
I'll turn off promiscuous mode and let you know if that helps.

>     <mailto:seanp.bennett@gmail.com>
>     >>     <mailto:seanp.bennett@gmail.com
>     >>     > email to ostinato+unsubscribe@googlegroups.com
>     <mailto:ostinato%2Bunsu...@googlegroups.com>
>     >>     <mailto:ostinato%2Bunsu...@googlegroups.com
>     <mailto:ostinato%252Bunsubscribe@googlegroups.com>>.

>     >>     > For more options, visit https://groups.google.com/d/optout
>     <https://groups.google.com/d/optout>
>     <https://groups.google.com/d/optout
>     <https://groups.google.com/d/optout>>.
>     >>
>     >>
>     >>
>     >>     --
>     >>     http://ostinato.org/
>     >>     @ostinato
>     >>
>     >>
>     >> --
>     >> Get Ostinato News and Updates on Twitter - Follow @ostinato
>     >> (http://twitter.com/ostinato)
>     >> ---
>     >> You received this message because you are subscribed to the Google
>     >> Groups "ostinato" group.
>     >> To unsubscribe from this group and stop receiving emails from it,
>     send

Sean Bennett

unread,
Mar 3, 2017, 9:01:04 AM3/3/17
to Carlos G Mendioroz, Srivats P, ostinato
Hi Carlos and Ostinato group,

I turned off Promiscuous mode on the vswitch, and it's still showing both packets.They look identical except for being milliseconds apart.

Srivats, you previously asked what the traffic looked like on the other side (WAN side) of the Gateway.  On the WAN side there is only 1 echo request.

I'm wondering if this is more likely a Wireshark issue and not Ostinato seeing as the Gateway only sees 1 packet.

-Sean

>     <mailto:seanp.bennett@gmail.com>
>     >>     <mailto:seanp.bennett@gmail.com
>     >>     > email to ostinato+unsubscribe@googlegroups.com
>     <mailto:ostinato%2Bunsu...@googlegroups.com>
>     >>     <mailto:ostinato%2Bunsu...@googlegroups.com
>     <mailto:ostinato%252Bunsubscribe@googlegroups.com>>.
>     >>     > For more options, visit https://groups.google.com/d/optout
>     <https://groups.google.com/d/optout>
>     <https://groups.google.com/d/optout
>     <https://groups.google.com/d/optout>>.
>     >>
>     >>
>     >>
>     >>     --
>     >>     http://ostinato.org/
>     >>     @ostinato
>     >>
>     >>
>     >> --
>     >> Get Ostinato News and Updates on Twitter - Follow @ostinato
>     >> (http://twitter.com/ostinato)
>     >> ---
>     >> You received this message because you are subscribed to the Google
>     >> Groups "ostinato" group.
>     >> To unsubscribe from this group and stop receiving emails from it,
>     send

Srivats P

unread,
Mar 4, 2017, 12:52:00 AM3/4/17
to Sean Bennett, Carlos G Mendioroz, ostinato
Sean,

Could you provide the Drone console log from the VM? You need to start
drone first on a different terminal before you start ostinato

http://ostinato.org/docs/faq#q-how-do-i-see-debug-console-logs-on-windows-platforms

Srivats
>> > <mailto:seanp....@gmail.com>
>> > >> <mailto:seanp....@gmail.com
>> > >> > email to ostinato+u...@googlegroups.com
>> > <mailto:ostinato%2Bunsu...@googlegroups.com>
>> > >> <mailto:ostinato%2Bunsu...@googlegroups.com
>> > <mailto:ostinato%252Buns...@googlegroups.com>>.
>> > >> > For more options, visit https://groups.google.com/d/optout
>> > <https://groups.google.com/d/optout>
>> > <https://groups.google.com/d/optout
>> > <https://groups.google.com/d/optout>>.
>> > >>
>> > >>
>> > >>
>> > >> --
>> > >> http://ostinato.org/
>> > >> @ostinato
>> > >>
>> > >>
>> > >> --
>> > >> Get Ostinato News and Updates on Twitter - Follow @ostinato
>> > >> (http://twitter.com/ostinato)
>> > >> ---
>> > >> You received this message because you are subscribed to the
>> > Google
>> > >> Groups "ostinato" group.
>> > >> To unsubscribe from this group and stop receiving emails from it,
>> > send
>> > <mailto:ostinato%2Bunsu...@googlegroups.com>>.
>> > >> For more options, visit https://groups.google.com/d/optout
>> > <https://groups.google.com/d/optout>.
>> > >
>> > > --
>> > > Carlos G Mendioroz <tr...@huapi.ba.ar <mailto:tr...@huapi.ba.ar>>
>> > LW7 EQI Argentina
>> >
>> >
>> >
>> > --
>> > http://ostinato.org/
>> > @ostinato
>> >
>> >
>>
>> --
>> Carlos G Mendioroz <tr...@huapi.ba.ar> LW7 EQI Argentina
>
>



--
http://ostinato.org/
@ostinato

Carlos Mendioroz

unread,
Mar 6, 2017, 8:30:19 AM3/6/17
to Sean Bennett, Srivats P, ostinato
I would say it's a pcap issue.
Both Ostinato and Wireshark are clients, Ostinato is injecting,
Wireshark is reading.
The inject side may be sending the copy to the reading client and to the
NIC, and the reading client is seeing it also at the NIC (driver?).

I've seen this on the past, can not remember now the details.
Once you know, it's not a big issue to live with :)

Sean Bennett @ 03/03/2017 10:59 -0400 dixit:
> > <mailto:psta...@gmail.com <mailto:psta...@gmail.com>>> wrote:
> >
> > The stream looks alright to me and is sending only 1 packet and not
> > looping either. When I open the stream on my Windows XP box, it just
> > sends one packet.
> >
> > When you transit this stream in Ostinato, how much does "Frames sent"
> > in the stats window for that port increase by?
> > What is the vNIC that you are using?
> > Is Wireshark capture running on the same Windows 2012 VM or on a
> > different box?
> >
> > Srivats
> >
> > On Thu, Feb 16, 2017 at 3:32 PM, Carlos G Mendioroz
> > <tr...@huapi.ba.ar <mailto:tr...@huapi.ba.ar> <mailto:tr...@huapi.ba.ar
> > >> On Thu, Feb 9, 2017 at 1:16 AM, <seanp....@gmail.com <mailto:seanp....@gmail.com>
> > <mailto:seanp....@gmail.com <mailto:seanp....@gmail.com>>
> > >> <mailto:seanp....@gmail.com
> <mailto:seanp....@gmail.com>
> > <mailto:seanp....@gmail.com
> > >> > email to ostinato+u...@googlegroups.com
> <mailto:ostinato%2Bunsu...@googlegroups.com>
> > <mailto:ostinato%2Bunsu...@googlegroups.com
> <mailto:ostinato%252Buns...@googlegroups.com>>
> > >> <mailto:ostinato%2Bunsu...@googlegroups.com
> <mailto:ostinato%252Buns...@googlegroups.com>
> > <mailto:ostinato%252Buns...@googlegroups.com
> <mailto:ostinato%25252Bun...@googlegroups.com>>>.
> > >> > For more options, visit https://groups.google.com/d/optout <https://groups.google.com/d/optout>
> > <https://groups.google.com/d/optout <https://groups.google.com/d/optout>>
> > <https://groups.google.com/d/optout <https://groups.google.com/d/optout>
> > <https://groups.google.com/d/optout
> <https://groups.google.com/d/optout>>>.
> > >>
> > >>
> > >>
> > >> --
> > >> http://ostinato.org/
> > >> @ostinato
> > >>
> > >>
> > >> --
> > >> Get Ostinato News and Updates on Twitter - Follow @ostinato
> > >> (http://twitter.com/ostinato)
> > >> ---
> > >> You received this message because you are subscribed to the Google
> > >> Groups "ostinato" group.
> > >> To unsubscribe from this group and stop receiving emails from it,
> > send
> > >> an email to ostinato+u...@googlegroups.com
> <mailto:ostinato%2Bunsu...@googlegroups.com>
> > <mailto:ostinato%2Bunsu...@googlegroups.com
> <mailto:ostinato%252Buns...@googlegroups.com>>
> > >> <mailto:ostinato+u...@googlegroups.com
> <mailto:ostinato%2Bunsu...@googlegroups.com>
> > <mailto:ostinato%2Bunsu...@googlegroups.com
> <mailto:ostinato%252Buns...@googlegroups.com>>>.
> > > Carlos G Mendioroz <tr...@huapi.ba.ar
> <mailto:tr...@huapi.ba.ar> <mailto:tr...@huapi.ba.ar
> <mailto:tr...@huapi.ba.ar>>>
> > LW7 EQI Argentina
> >
> >
> >
> > --
> > http://ostinato.org/
> > @ostinato
> >
> >
>
> --
> Carlos G Mendioroz <tr...@huapi.ba.ar <mailto:tr...@huapi.ba.ar>>
> LW7 EQI Argentina
>
>

--
Reply all
Reply to author
Forward
0 new messages