Wireshark mailing list archives
Re: How does wireshark identify tcp streams?
From: Guy Harris <guy () alum mit edu>
Date: Sat, 21 May 2011 11:15:29 -0700
On May 21, 2011, at 11:12 AM, Irfan Habib wrote:
Wireshark assigns numbers to tcp streams in a pcap file and packets can be filtered based on that tcp stream number. My question is, what properties in a packet does wireshark use to determine which tcp stream it is part of?
Source and destination IP addresses and TCP port numbers. ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- How does wireshark identify tcp streams? Irfan Habib (May 21)
- Re: How does wireshark identify tcp streams? Guy Harris (May 21)
- Re: How does wireshark identify tcp streams? Irfan Habib (May 21)
- Re: How does wireshark identify tcp streams? Jaap Keuter (May 21)
- Re: How does wireshark identify tcp streams? Irfan Habib (May 21)
- Re: How does wireshark identify tcp streams? Guy Harris (May 21)