Wireshark-users: [Wireshark-users] SMB parser and TCP retransmission issues
From: Mohan Narayanaswamy <mohann@xxxxxxxxxxxxxxx>
Date: Thu, 15 Oct 2009 00:35:14 -0700

Hi there,

 

Wireshark SMB parser does not seem to work well when there is a TCP retransmitted segment.

 

I am capturing SMB traffic between host A and host B on a network with little bit of loss.  When there are retransmitted TCP segments, Wireshark does not seem to decode those segments as SMB messages.

 

Does anyone know how  to fix this ? Any help would be appreciated.

 

Thanks,

Mohan