Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Missing TCP Flags

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Wed, 08 Sep 2010 19:00:05 +0200

Hi,

Wireshark version?
Sample caption?

Thanks,
Jaap

On Wed, 8 Sep 2010 14:37:58 +0100, "Scheffenegger, Richard" <rs@xxxxxxxxxx> wrote:


Hi,

I have here a trace with the RFC3540 ECN Nounce. That (valid) TCP Flag is one of the lower 4 bits where the TCP options length is also stored; however, Wireshare doesn't seem to decode the full 12-bit TCP Flags field properly - only the lower 8 bits are shown.

Does anyone know how to fix this, so that the full 12 bit field is decoded (3 reserved bits, ECN, CWR, ECE, URG, ACK, PSH, RST, SYN, FIN )?

Thanks,

Richard Scheffenegger