On Wed, Sep 19, 2007 at 11:09:41AM +0200, Marcin wrote:
> Is there a way to merge all the fragmented IP packets and them output
> them into separate trace? I Would need smth. like:
> tshark ???r intrace ???w outrace
> to have all the packets merged inside the outrace. I then need to access
> full payload of the merged packets.
In a newly installed setting wireshark (and tshark) will automagically
reassemble fragmented ip packets: The last fragment will dissect like
the whole packet. This behaviour can be changed via preferences.
ciao
Joerg
--
Joerg Mayer <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.