Wireshark-users: [Wireshark-users] Large TCP packets
From: Martin Andersson <[email protected]>
Date: Wed, 25 Jun 2008 20:54:43 +0200
Hello

I have a capture with very large tcp packets (it's a ftp session). My concern is that I can't see any IP fragments. The whole TCP packets is visible in wireshark, I expected to see the IP fragments. Can't figure out how this works.
Also should the MSS not be followed by the TCP stack in the server.

The capture is done on the ftp-server side (opensuse 10.2), the client is an windows machine.
tshark -i eth0 host 10.3.0.86

/Martin

Attachment: LargePkts.pcap.gz
Description: application/gzip