Hi wireshark supporter,
I installed wireshark software on my Ubuntu 16.04, and when I using tshark to capture packets, I found that one of the sip packet which is more than 1500bytes is fragmented as two ip packets.
But if I using wireshark to capture all the sip packets can be shown completely, the bigger sip packet which is more than 1500 bytes can be displayed in one packet in wireshark.
My tshark and wireshark version is 2.2.6.
So I’m confused, then I checked the preference of wireshark, and found that ip reassembly is enabled by default,