Wireshark-users: Re: [Wireshark-users] Disabling TCP reassembly does not work
From: Bill Meier <wmeier@xxxxxxxxxxx>
Date: Wed, 18 Feb 2009 19:24:32 -0500
wsgd wrote:
I wanted to say that
 the packets (with size = 2974 or 4434 or ...) we see into wireshark
 are the real packets received from the network (through winpcap or ...).
I really think Wireshark do NOT reassemble them.

Perhaps you can check with another tool (windump for example).



For some possibilities see the EMail thread starting with:

http://www.wireshark.org/lists/wireshark-users/200806/msg00245.html