Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5454] "tcp" display filter not working

Date Prev · Date Next · Thread Prev · Thread Next
Date: Tue, 30 Nov 2010 16:21:53 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5454

Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |INVALID

--- Comment #2 from Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx> 2010-11-30 17:21:53 MST ---
Thanks for your report.  This is because that ICMP packet has a copy of the
first part of the TCP/IP packet that the ICMP destination unreachable message
is referring to.  If you expand the tree under Internet Control Message
Protocol, you'll see the "Internet Protocol" headers and then part of the
"Transmission Control Protocol" headers, so Wireshark treats it as having TCP
even though it's encapsulated in ICMP.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.