Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Multiple Packets in One TCP Segment

From: Susan Ditmore <sditmore@xxxxxxxxx>
Date: Fri, 14 Aug 2009 16:56:04 -0400
Hello,

I am developing a packet dissector plugin for Wireshark. The packets I am dissecting do not specify their length in their header, but they are terminated by a special character (and can be a variable length). Additionally, multiple complete packets of the protocol may arrive in one tcp segment. I would like to know how to tell wireshark to divide up these packets. I understand there is a command called tcp_dissect_pdus(), but I believe it needs the length specified in the header. Is this correct?

Sincerely,

Susan Ditmore
--
"To categorize is human; to distribute, divine."