Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] Re: ICMP

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Hansang Bae <hbae@xxxxxxxxxx>
Date: Tue, 22 Mar 2005 01:00:49 -0500
On 11:25 PM 3/21/2005, Bob Snyder wrote:
>[snip]
>The argument that you can use "udp and not icmp" to only see the original UDP seems backwards to me. You should be able to use "udp" to see only the UDP, and "udp and icmp" when you want to see both. Surely that is more intuitive.
>
>That said, I think using the UDP (or whatever) dissector to decode the header data included in the ICMP messages is brilliant :-)


The next time you troubleshoot PMTU-D problem (YET AGAIN!!!) you'll thank Ethereal for putting it in there!

hsb