Wireshark-users: Re: [Wireshark-users] What does “Raw packet data” field mean in Wireshark?
From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Tue, 20 Sep 2016 14:41:43 -0500
Hi,

The ‘Raw packet data' means that there’s no link layer information available, just upper (in this can network) layer information.

Thanks,
Jaap

> On 17 Sep 2016, at 22:06, 江杰 <jie.jiang@xxxxxxxxxx> wrote:
> 
> <屏幕快照 2016-09-13 下午8.52.23.png>
> 
> <屏幕快照 2016-09-13 下午8.53.04.png>
> 
> As you can see in first figure, what does that Raw packet data mean? What is the difference between normal tcp packet in figure 2?
> 
> FYI, I'm using Wireshark 2.2.0.
> 
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    https://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe