Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Fragmented packets

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "ronnie sahlberg" <ronniesahlberg@xxxxxxxxx>
Date: Tue, 3 Oct 2006 11:24:34 +1000

Note that IP Fragment Reassembly will only work if you have captured the full packets.

If you have only captured partial packets (specifying snaplength less than the local MTU) it will not be possible to reassemble the fragments.


On 10/3/06, Martin Regner <martin.regner@xxxxxxxxx> wrote:
Dennis Tate wrote:
<The only problem is that some of the packets, due to the size of the message are fragmented, which the SNMP decoder cannot process.
 
Do you have "Reassemble fragmented IP datagrams" checkbox checked in Edit/Preferences.../Protocols/IP ?
 
 
Best regards,
   Martin

_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users


  • References:
    • [Wireshark-users] Fragmented packets
      • From: Tate, Denis - UK
    • Re: [Wireshark-users] Fragmented packets
      • From: Martin Regner
  • Prev by Date: Re: [Wireshark-users] Wireshark on OppenBSD 4.0
  • Next by Date: Re: [Wireshark-users] Wireshark on OppenBSD 4.0
  • Previous by thread: Re: [Wireshark-users] Fragmented packets
  • Next by thread: Re: [Wireshark-users] IP Data checksum
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation