Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] How to view TCP responses

From: Steinar Bang <sb@xxxxxx>
Date: Wed, 09 Apr 2008 10:27:19 +0200
Platform: Intel Pentium M, Ubuntu 7.10,
	  wireshark 0.99.6rel-3ubuntu0.1

I've captured an HTTP/1.1 connection on port 33333, using the filter
	port 33333

I've also right clicked the capture, and selected
	Decode As...
and chosen to decode the TCP capture as HTTP.

In the capture field I see the HTTP request packages, and when I do 
	Follow TCP Stream
I see both the quest and the response.

However, in the capture packet list I only see the packets related to
the TCP connection itself, and the "payload" for the HTTP request.  I
can't find the response "payload" anywhere.

Obviously the packes are in the capture, because otherwise their content
wouldn't have been in the "Follow TCP Stream" result.

Is there a way I can look at the response packages in the dissector?

Thanx!


- Steinar