Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Query about TCP reassembly

From: Munish Dayal <munish.dayal@xxxxxxxxxxx>
Date: Wed, 15 Jul 2009 18:46:05 +0530
Hi,
 
I have a protocol (lets call it "myproto") that runs atop TCP, and myproto messages are coming split across multiple TCP segments.
I have to reassemble myproto messages, that are variable in size.
 
myproto message header does not contain any length information about the total size of myproto message.
From the myproto message header I can only know if it is the last message fragment or there is more fragment to follow.
I have to reassemble myproto message fragments till I get a fragment that says it is the last one.
 
Can I use tcp_dissect_pdus() in this case?
If yes, how ?
If no, what is the way to reassemble such a protocol.
 
Thanks,
Munish


"DISCLAIMER: This message is proprietary to Aricent and is intended solely for the use of the individual to whom it is addressed. It may contain privileged or confidential information and should not be circulated or used for any purpose other than for what it is intended. If you have received this message in error,please notify the originator immediately. If you are not the intended recipient, you are notified that you are strictly prohibited from using, copying, altering, or disclosing the contents of this message. Aricent accepts no responsibility for loss or damage arising from the use of the information transmitted by this email including damage from virus."