Wireshark bit me today….

So I was playing with some captures of fragmented packets. My interest was in observing the offset values, and the more fragments bit. I was sending ICMP messages with a size of 2544.

ICMP Ping

 

 

This will obviously be fragmented because it is bigger than my default MTU. When I took a look at the capture this is what I saw.

ICMP filtered

 

Where are my fragments?????

ICMP unfiltered

 

Oh there they are. For some reason they are classified at IPv4 instead of ICMP…how very annoying. If anyone knows why let me know.

 

Advertisements
Posted in Uncategorized

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: