Wireshark-users: Re: [Wireshark-users] Using Wireshark for IP fragments reassembling
Yes, Guy understands my question properly.
Any original idea how to save reassembled packets?
Thanks,
Irine.
-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Hans Nilsson
Sent: Tuesday, January 09, 2007 10:41
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Using Wireshark for IP fragments
reassembling
Aha. Well maybe exporting the packets and then doing some magic with
text2pcap or something like that is possible?
On Mon, 8 Jan 2007 23:50:54 -0800, "Guy Harris" <guy@xxxxxxxxxxxx> said:
>
> On Jan 8, 2007, at 11:38 PM, Hans Nilsson wrote:
>
> > It doesn't? I can both export the packet bytes and use "Follow TCP
> > Stream" on reassembled IP-packets. But maybe I'm misunderstanding
> > something.
>
> You can export the packet bytes of an individual reassembled IP
packet.
>
> You can't save a capture file the packets of which are reassembled IP
> packets, which is what I suspect the person who asked the original
> question wanted.
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users
--
Hans Nilsson
hasse_gg@xxxxxxxx
--
http://www.fastmail.fm - Send your email first class
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users
__________________________________________________________________________________________
This electronic message contains information from Verint Systems, which may be privileged and confidential.
The information is intended to be for the use of the individual(s)or entity named above.
If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited.
If you have received this electronic message in error, please notify us by replying to this email (1).