I have two capture taken on two laptops at either end of a client/server scenario. I want to merge them to use later with the new compare feature on Wireshark's Statistics menu. Neither trace has any TCP analysis flags set, other than a few window size updates & 1 retransmission.
However, when I merge them with Mergecap chronologically, I end up with about 400 TCP window size updates, duplicate acks & retransmissions etc.
I have tried this on several different trace scenarios and get similar results. Why doe this happen?
Keith French.