Wireshark-users: Re: [Wireshark-users] 6lowpan fragmented packet dissecting(or reassemble) proble

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Fri, 3 Mar 2017 13:28:53 +0100
Hi,

Thanks for providing the capture. A quick look with Wireshark 2.2.4 at packet 27 reveal the same problem I assume.
When looking at the numbers my first guess would be that the last fragment (in packet 27) isn’t added to the reassembled payload before being passed to the IPv6 dissector. Therefore the UDPv6 dissector comes up short.

I would suggest filing a bug report (https://bugzilla.wireshark.org) with this capture file and a proper description, so that it can be investigated further and possibly solved with a code change.

Thanks,
Jaap

On 3 Mar 2017, at 08:35, H Jin Ko <ymir.kr@xxxxxxxxx> wrote:

Hi Jaap.

Prior dump contains personal information, so I attached new dump.
Thanks for help.

- H.Jin


On Fri, Mar 3, 2017 at 4:07 PM, Jaap Keuter <jaap.keuter@xxxxxxxxx> wrote:
Hi,

Can you provide a sample capture file with these frames? That works much easier than a text dump only.

Thanks,
Jaap


On 2 Mar 2017, at 09:29, H Jin Ko <ymir.kr@xxxxxxxxx> wrote:

Hello list.

I'm writing PANA protocol in the ZigBee environment.
When I attempt to analysis protocol, wireshark said fragemented packet
is malformed, but I can't see the why.
(Dissecting unfragmented packet is OK.)

...................
</snip>