Wireshark-users: Re: [Wireshark-users] Assembling of fragmented IP protocol packets
From: "Franz Edler" <franz.edler@xxxxxxxx>
Date: Tue, 24 Apr 2007 20:40:53 +0200
Hi,
 
> Did you by any chance use a filter with port numbers? Since port numbers
> are only present in the IP-fragment that has the UDP/TCP header in it
> all the other fragments are not seen by the filter.
Yes. I used a port filter.

> If you only filter on ip-addresses you should be fine though :)
I will just try it again.

> Hope this helps,   Cheers,
This would be fine.

-franz