Wireshark mailing list archives

Re: Wireshark not reassembling UDP packet


From: Michael Tuexen <Michael.Tuexen () lurchi franken de>
Date: Tue, 24 Apr 2012 21:22:56 +0200

On Apr 24, 2012, at 8:36 PM, Sake Blok wrote:

On 24 apr 2012, at 17:42, Andre Kostur wrote:

Yep, Frame length and Capture length are 1514 bytes.  UDP checksum validation is already disabled.  Additional 
information, the capture was done on the same box as the packet transmitter.   Doing the capture from a 3rd box, and 
wireshark is able to reassemble the packet.

It should also work on the box itself. Are you able to post the capture file so we can have a look at why it is 
failing?
UDP doesn't do fragmentation and reassembly. So I guess you need IP level reassembly. One possibility
is that the IP header checksum is not correct due to offloading. Does trying to disable the IP header checksum
validation help?

Best regards
Michael

Cheers,
Sake
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request () wireshark org?subject=unsubscribe


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: