Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 3049] New: In consistency in dissecting IP

Date: Mon, 10 Nov 2008 02:17:10 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3049

           Summary: In consistency in dissecting IP
           Product: Wireshark
           Version: 0.99.6
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Minor
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: ch_nbc@xxxxxxxxxxx


Created an attachment (id=2469)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2469)
Message dump 

Build Information:
Paste the COMPLETE build information from "Help->About Wireshark", "wireshark
-v", or "tshark -v".
--
While dissecting IP, wireshark seems in consistence with the messages 


 1. If the packet size is 5 bytes or more, it is displayed as an "IP fragment".
 If the packet size is 4 bytes or less, it is displayed as "IP".  
 Should it also be displayed as an IP fragment?

 2. If the packet size is anywhere from 1 to 4 bytes, there are no 
 "data" bytes displayed.  Is DOPA treating this as CRC?  if so, that 
 does not seem to be consistent with packet sizes greater than 4 bytes.

Please find the message dump attached


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.