Wireshark-users: [Wireshark-users] Can Anyone Tell Me What the HELL is Going on with My Capture?
From: "Robinson, Eric" <eric.robinson@xxxxxxxxx>
Date: Fri, 30 Jan 2009 10:00:52 -0800
Today I captured an exchange between a client and a tomcat server using
ethereal-gnome-0.99.0-EL4.2 on the server (a Linux box).

The trace shows the client connecting to the server and saying "My MSS
is 1460" which is of course perfectly normal.

But then I see several 4000+ byte frames going from the server to the
client. Yes, frames. The MTU on the interface (bond0) is only 1500. Can
anyone tell me how this is possible? Is Ethereal is just acting up?

I know this is technically the WireShark list, not the Ethereal list,
but I was hoping it is still the right place to ask.

--Eric


And now, the annoying server-appended corporate disclaimer
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv


Disclaimer - January 30, 2009 
This email and any files transmitted with it are confidential and intended solely for wireshark-users@xxxxxxxxxxxxx. If you are not the named addressee you should not disseminate, distribute, copy or alter this email. Any views or opinions presented in this email are solely those of the author and might not represent those of . Warning: Although  has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments. 
This disclaimer was added by Policy Patrol: http://www.policypatrol.com/