Wireshark-users: Re: [Wireshark-users] Wireshark not reassembling UDP packet

From: Michael Tuexen <Michael.Tuexen@xxxxxxxxxxxxxxxxx>
Date: Tue, 24 Apr 2012 21:22:56 +0200
On Apr 24, 2012, at 8:36 PM, Sake Blok wrote:

> On 24 apr 2012, at 17:42, Andre Kostur wrote:
> 
>> Yep, Frame length and Capture length are 1514 bytes.  UDP checksum validation is already disabled.  Additional information, the capture was done on the same box as the packet transmitter.   Doing the capture from a 3rd box, and wireshark is able to reassemble the packet.
> 
> It should also work on the box itself. Are you able to post the capture file so we can have a look at why it is failing?
UDP doesn't do fragmentation and reassembly. So I guess you need IP level reassembly. One possibility
is that the IP header checksum is not correct due to offloading. Does trying to disable the IP header checksum
validation help?

Best regards
Michael
> 
> Cheers,
> Sake
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>