Wireshark-users: Re: [Wireshark-users] Wireshark not reassembling UDP packet
From: Kevin Cullimore <kcullimo@xxxxxxxxxx>
Date: Fri, 27 Apr 2012 07:35:50 -0400
On 4/24/2012 5:40 PM, ronnie sahlberg wrote:
On Wed, Apr 25, 2012 at 5:22 AM, Michael Tuexen
<Michael.Tuexen@xxxxxxxxxxxxxxxxx>  wrote:
On Apr 24, 2012, at 8:36 PM, Sake Blok wrote:

On 24 apr 2012, at 17:42, Andre Kostur wrote:

Yep, Frame length and Capture length are 1514 bytes.  UDP checksum validation is already disabled.  Additional information, the capture was done on the same box as the packet transmitter.   Doing the capture from a 3rd box, and wireshark is able to reassemble the packet.
It should also work on the box itself. Are you able to post the capture file so we can have a look at why it is failing?
UDP doesn't do fragmentation and reassembly. So I guess you need IP level reassembly. One possibility
is that the IP header checksum is not correct due to offloading. Does trying to disable the IP header checksum
validation help?

In the reassembly, we could remove the check whether the ip header
checksum is correct or not.
Genuinely invalid cheksums should be incredibly rare today  versus
being uninitialized/garbage due to offload.
Is it possible to configure an option to turn the check on/off?
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
              mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe