Wireshark mailing list archives
DNP3 message spanning multiple TCP packets bug
From: Graeme Melia <graeme.melia () ntlworld com>
Date: Tue, 05 Jul 2011 21:42:20 +0100
I am using Wireshark to to monitor a multi-serial port device that communicates to a server via IP. The outgoing TCP messages from the server has the DNP3 message embedded, usually in one packet. The incoming DNP3 messages are being broken up so that each byte is a single TCP packet, or a 23 byte DNP3 message becomes 23 TCP packets each with a payload of 1 data byte. The problem is that the Wireshark DNP3 dissector is not reassembling the original DNP3 message. I have checked the DNP3 option to reassemble messages split across multiple TCP packets and the TCP setting to allow subdissector to reassemble TCP streams. Is this a bug or have I missed something? ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- DNP3 message spanning multiple TCP packets bug Graeme Melia (Jul 05)
- Re: DNP3 message spanning multiple TCP packets bug Sake Blok (Jul 05)
- Re: DNP3 message spanning multiple TCP packets bug Graham Bloice (Jul 06)
- Re: DNP3 message spanning multiple TCP packets bug Graham Bloice (Jul 07)
- Re: DNP3 message spanning multiple TCP packets bug Chris Maynard (Jul 07)
- <Possible follow-ups>
- Re: DNP3 message spanning multiple TCP packets bug Graeme Melia (Jul 06)
- Re: DNP3 message spanning multiple TCP packets bug Boonie (Jul 06)
- Re: DNP3 message spanning multiple TCP packets bug Sake Blok (Jul 05)