https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3315
--- Comment #16 from Jeff Morriss <jeff.morriss.ws@xxxxxxxxx> 2012-02-23 11:00:15 PST ---
(In reply to comment #15)
> I tried the resolution mentioned in Comment 3 (except I used udp.port==5060 &&
> udp.length>0 for the sip protocol). This still didn't work.
In your case (from bug 6864) it was *IP* reassembly that was involved. So
you'd have to get all the IP fragments. I'm not immediately sure how to filter
much of anything out and still get the IP fragments (okay a simple filter like
"ip" would work but I don't think you'd end up filtering much out in that
case).
> Is this an item that can be fixed in Wireshark, or some patch that can be
> applied? This functionality is extremely useful in analyzing data and
> filtering down to an email-friendly size.
No patch yet. It is not, I think, an easy problem to solve (which is why the
bug is still here and open).
--
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are watching all bug changes.