Wireshark-dev: [Wireshark-dev] Packet reassembling
From: Gerhard Gappmeier <[email protected]>
Date: Tue, 11 Jul 2006 18:07:22 +0200

I have read the chapter about packet reassembling.
It's clear except from one point.

If a server has multiple TCP connections to different clients,
the captured packets can be mixed up from different messages.
How is this kept in mind?
Is this tracked automagically by "fragment_add_seq_check" with the contents of the "packet_info" structure,
or is the example in the docs not taking this into account?
Is one instance of the "msg_fragment_table" and "msg_reassembled_table enough" for multiple connections?
Or do I need one for each connection?

I see at least a problem with the sequence numbers.
At least my protocol has no sequence number for different chunks,
so I have to do something like "connection[i].seq_number++" for each connection.
Are there any recommendations?

mit freundlichen Grüßen / best regards

Gerhard Gappmeier
ascolab GmbH - automation system communication laboratory
