Wireshark mailing list archives

tcp reassembly


From: Chun Chan <chun_chan () ymail com>
Date: Wed, 16 Dec 2009 13:27:26 -0800 (PST)

Hi
I am writing a sniffer but I couldnt understand some things about tcp reassembly.
firstly I send a data via socket 5000 bytes. then tcpip stack split into three tcp packets. but this is not ip 
fragmentation. I think this is tcp segmentation.
but I can not understand when I will sniff this packet How can I defragment this packet? 
I need to understand when finished 5000 bytes.
I will waiting your reply
thanks



      
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: