Is there anything I can colelct for you that might help understand why yhis is happening?
THe platform is Mac Mac-mini:Traces root$ tcpdump -h tcpdump version tcpdump version 4.9.2 -- Apple version 83.200.2 libpcap version 1.8.1 -- Apple version 79.200.4 LibreSSL 2.2.7 System Version: macOS 10.14.3 (18D42) Kernel Version: Darwin 18.2.0 From what I can determine, only running pcapsipdump watching the interface does this. Passing the pcap files manually I don't see the issue. Thanks
Strange negative timestamp on one packet