Hi,
In wireshark it is possible to detect a TCP checksum error at capture time by using the tcp.checksum_bad == 1.
How
can it be done with tshark? I would like to write to a file only the
received TCP packets with a wrong TCP checksum, but it does not look
like it can be done at once. Should I use 2 shark instances, one
capturing the tcp packets and the other using the display filter to
filter the packets with wrong TCP checksum? Are there some examples
about how to use tshark to do such things?
Thanks for your help
BRs,
Jimmy