Wireshark-users: Re: [Wireshark-users] How does wireshark identify tcp streams?

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Sat, 21 May 2011 21:06:11 +0200
Hi, 

You forgot the TCP port numbers. 

Thanks,
Jaap

Send from my iPhone

On 21 mei 2011, at 20:48, Irfan Habib <irfan@xxxxxxxxxxxxxx> wrote:

But those would be identical for all traffic b/w a single source/Dest Ip Address

-- 
Best Regards,
Irfan

On Saturday, 21 May 2011 at 19:15, Guy Harris wrote:


On May 21, 2011, at 11:12 AM, Irfan Habib wrote:

Wireshark assigns numbers to tcp streams in a pcap file and packets can be filtered based on that tcp stream number. My question is, what properties in a packet does wireshark use to determine which tcp stream it is part of?

Source and destination IP addresses and TCP port numbers.
___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe