Wireshark bit me today….

So I was playing with some captures of fragmented packets. My interest was in observing the offset values, and the more fragments bit. I was sending ICMP messages with a size of 2544.




This will obviously be fragmented because it is bigger than my default MTU. When I took a look at the capture this is what I saw.

ICMP filtered


Where are my fragments?????

ICMP unfiltered


Oh there they are. For some reason they are classified at IPv4 instead of ICMP…how very annoying. If anyone knows why let me know.


Posted in Uncategorized

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s

%d bloggers like this: