Wireshark-users: [Wireshark-users] How to understand "ip.fragment" and "ip.fragments" display fil

Date Prev · Date Next · Thread Prev · Thread Next
From: Nan Xiao <xiaonan830818@xxxxxxxxx>
Date: Thu, 9 Jun 2022 14:29:53 +0800
Hi Community,

Greetings from me!

I am trying to understand the meaning of "ip.fragment" and "ip.fragments" display filters, but unfortunately it seems I can't find answers from user manual (https://www.wireshark.org/docs/wsug_html_chunked/index.html). E.g., the attachment pcap file includes 2 fragment packets, and both  "ip.fragment" and "ip.fragments" filters will make the 2nd packet display, and this makes me confused the differences between  "ip.fragment" and "ip.fragments" display filters.

Anyone can give some explanations? Thanks very much in advance!

Best Regards
Nan Xiao

Attachment: fragment.pcap
Description: Binary data