Wireshark detects duplicate IPs in the ARP protocol. Use the arp.duplicate-address-frame
Wireshark filter to display only duplicate IP information frames.
For example, open the ARP_Duplicate_IP.pcap
file and apply the arp.duplicate-address-frame
filter, as shown in the screenshot:
Wireshark is providing the following information in this case:
fa:16:3e:bf:22:d0
and shows as a duplicate of that IP address.3.142.12.170