Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Regarding reassembly of segmented packets.

From: Nilesh Tayade <nilesh.tayade85@xxxxxxxxx>
Date: Mon, 24 Oct 2011 11:59:37 +0530
Hi,

I am looking at some of the HTTPS traces and I saw there are many
packets segmented when large chunk of data is coming.
However, Wireshark displays both - the segments and then the reassembled
packet.

Could someone please provide a pointer how Wireshark does it? What is
the logic it applies in reassembling the relevant segments only?
Basically I am not able to understand how it keeps the end-of-record mark.

--
Thanks,
Nilesh