Wireshark-users: Re: [Wireshark-users] fragmented IP packets

From: Joerg Mayer <jmayer@xxxxxxxxx>
Date: Wed, 19 Sep 2007 11:30:00 +0200
On Wed, Sep 19, 2007 at 11:09:41AM +0200, Marcin wrote:
> Is there a way to merge all the fragmented IP packets and them output 
> them into separate trace? I Would need smth. like:
> tshark ???r intrace ???w outrace
> to have all the packets merged inside the outrace. I then need to access 
> full payload of the merged packets.

In a newly installed setting wireshark (and tshark) will automagically
reassemble fragmented ip packets: The last fragment will dissect like
the whole packet. This behaviour can be changed via preferences.

 ciao
    Joerg
-- 
Joerg Mayer                                           <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.