npcap v1.10 blocks VM network (VNET1) on Windows 10 until 2nd tracing with Wireshark is started
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 3.6k
- Forks
- 592
- PR merge metrics
- No merged PRs in 30d
Description
Environment is
- Thinkpad X1 Carbon with 16GB RAM
- Windows 10 Pro (1909)
- VMWare Workstation 15.5
- Archlinux as VMWare guest connected via "Host only network" (VNET1 adapter), IP4 192.168.111.0/24 and host IP 192.168.111.111
- Wireshark 3.4.2
- npcap V1.10
- (previously WinPCap V4.1.3)
This all worked fine until I changed from WinPCap 4.1.3 to npcap 1.10. Since changing to npcap, the Archlinux VMWare guest cannot be reached from the Windows host until Wireshark is started and a trace of the VNET1 adapter is started twice!
I uninstalled npcap and reinstalled WinPCap, and everthing works as desired. Then uninstall WinPCap, and install npcap again, and the problem is back. So it is definitely a problem with npcap.
Some more details:
- The Archlinux guest is suspended, then restarted. So it is not shutdown across (re-)installs, or Windows reboots.
- A ping to Archlinux (192.168.111.111) succeeds in every scenartio with WinPCap, but is blocked (timeout) with npcap.
- Tracing the WLAN adapter with Wireshark works but does not help the VNET1 network.
- Tracing the VNET1 adapter with Wireshark does not help the VNET1 network. The pings are not seen in the trace,
- Stopping the VNET1 trace and starting a second time resolves the network problem. Pings are now seen in Wireshark, and pings are now responded by Archlinux guest.
- Connection to Archlinux guest thereafter succeeds even without Wireshark running, until Windows is rebooted.
- Accessing the internet from Windows works in any case, so the problem seems to occur with the virtual adapter(s), only.
- I tried both, installing npcap in "WinPcap API-compatible mode", and in non-compatible mode. No difference.
Is there anything I can do?
I'm going to reinstall WinPcap for the time being, but will of course try out whatever you suggest, and will send more docmentation upon request.
TIA
Peter
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the Windows 10, VMware Workstation, Archlinux guest, VNET1, Wireshark, and npcap 1.10 setup described in the report, comparing it with WinPcap 4.1.3. Investigate the behavior across reboot and the first and second Wireshark traces; done means the VNET1 guest is reachable after reboot without starting a second trace.
Written by the indexing model from the issue text.
Assessment
- Domain
- networking, operating-systems
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100