Hi,
Talk of nitty gritty, there are no reassembled packets, just reassembled
IP fragments (if that is the layer the fragmentation occurs).
You can get that data from the reassembled message tab under the packet
bytes pane.
Thanx,
Jaap
On Tue, 9 Jan 2007, Kaplan, Irine wrote:
>
> Yes, Guy understands my question properly.
> Any original idea how to save reassembled packets?
> Thanks,
> Irine.
>
> -----Original Message-----
> From: wireshark-users-bounces@xxxxxxxxxxxxx
> [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Hans Nilsson
> Sent: Tuesday, January 09, 2007 10:41
> To: Community support list for Wireshark
> Subject: Re: [Wireshark-users] Using Wireshark for IP fragments
> reassembling
>
> Aha. Well maybe exporting the packets and then doing some magic with
> text2pcap or something like that is possible?
>
> On Mon, 8 Jan 2007 23:50:54 -0800, "Guy Harris" <guy@xxxxxxxxxxxx> said:
> >
> > On Jan 8, 2007, at 11:38 PM, Hans Nilsson wrote:
> >
> > > It doesn't? I can both export the packet bytes and use "Follow TCP
> > > Stream" on reassembled IP-packets. But maybe I'm misunderstanding
> > > something.
> >
> > You can export the packet bytes of an individual reassembled IP
> packet.
> >
> > You can't save a capture file the packets of which are reassembled IP
>
> > packets, which is what I suspect the person who asked the original
> > question wanted.
> > _______________________________________________
> > Wireshark-users mailing list
> > Wireshark-users@xxxxxxxxxxxxx
> > http://www.wireshark.org/mailman/listinfo/wireshark-users
> --
> Hans Nilsson
> hasse_gg@xxxxxxxx
>
> --
> http://www.fastmail.fm - Send your email first class
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users
>
> __________________________________________________________________________________________
> This electronic message contains information from Verint Systems, which may be privileged and confidential.
> The information is intended to be for the use of the individual(s)or entity named above.
> If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited.
> If you have received this electronic message in error, please notify us by replying to this email (1).
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users
>
>