Wireshark-users: [Wireshark-users] Capturing only packets with bad TCP Checksum
From: Martin Isaksson <martin.isaksson@xxxxxxxxxxxx>
Date: Mon, 5 Nov 2012 22:34:34 +0100
Hi,
 
Is there any way of creating a capturing filter to only get packets that have a bad TCP checksum?
Or am I better off creating a circular buffer of files and postprocessing with display filters them to save only the bad segments (and then merge with mergecap at the end)?
 
Thanks,
Martin