Wireshark-dev: Re: [Wireshark-dev] Npcap 0.04 call for test

From: Pascal Quantin <pascal.quantin@xxxxxxxxx>
Date: Thu, 27 Aug 2015 22:17:09 +0200

2015-08-25 12:00 GMT+02:00 Yang Luo <hsluoyb@xxxxxxxxx>:
Hi Guy,

Now PCAP_IF_LOOPBACK flag in pcap_if_t struct will be set for "Npcap Loopback Adapter" both for DLT_NULL mode and Fake Ethernet mode.
See Npcap 0.04 r8 at:

Cheers,
Yang

Hi Yang,

I noticed an issue when running Npcap 0.4r8 with DLT_NULL option on my Windows 10 x64 host. After putting my laptop in standby mode and resuming my session, when launching Wireshark the Npcap loopback interface is no more working as expected:
- the capture is no more done with Null/Loopback encapsulation type, but with Ethernet type using a MAC address 02:00:4c:4f:4f:50
- pinging loopback address is no more captured
- when checking the interface characteristics with Wireshark GTK UI, the media supported is Ethernet instead of Null/Loopback
Rebooting the PC solves the issue. Any idea on how to investigate this?

You will find attached th corresponding DebugView log when launching Wireshark.

Cheers,
Pascal.

Attachment: npcap_0.04r8.zip
Description: Zip archive