Wireshark-users: Re: [Wireshark-users] Wireshark fails to display UDP packets

From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Thu, 1 Dec 2011 10:59:55 -0700
On Thu, Dec 01, 2011 at 11:20:59PM +0530, PRASANTH RAJAGOPAL wrote:

> dissecting until the IP layer, but not beyond that. I saw that some 
> packets emitted by other computer is seen as UDP. I have attached a 
> screenshot explaining what I mean.

Attaching a short packet capture is better than a large (compared to the 
e-mail text) image file.

> What I don't understand is, why wireshark does not detect UDP 
> protocol, when IP protocol has already detected it. Maybe that will 
> help me see what mistake is done in the frame.

I suspect it is because the packets are fragmented IP.  Do you have the 
"reassemble fragmented IPv4 datagrams" preference enabled under the IPv4 
protocol preferences?