Difference between revisions of "Wireshark does not show fragmented SIP packets"
From Kolmisoft Wiki
Jump to navigationJump to search
Line 2: | Line 2: | ||
'''Wireshark''' does not show fragmented SIP packets (usually INVITE packets), it looks like this in the Wireshark interface: | '''Wireshark''' does not show fragmented SIP packets (usually INVITE packets), it looks like this in the Wireshark interface: | ||
[[File: | [[File:wireshark_fragmented_pcap.png]]<br> | ||
<br><br> | <br><br> | ||
Line 9: | Line 9: | ||
The option is available under Edit --> Preferences --> Protocols --> IPv4 window | The option is available under Edit --> Preferences --> Protocols --> IPv4 window | ||
[[File:wireshark_reassemble_setting.png]]<br> | |||
With the option '''Reassemble fragmented IP datagrams'''' disabled, Wireshark will display a fragmented SIP message | With the option '''Reassemble fragmented IP datagrams'''' disabled, Wireshark will display a fragmented SIP message | ||
[[File:wireshark_not_fragmented_pcap.png]]<br> | [[File:wireshark_not_fragmented_pcap.png]]<br> |
Revision as of 08:40, 6 December 2022
The Problem
Wireshark does not show fragmented SIP packets (usually INVITE packets), it looks like this in the Wireshark interface:
The Solution
Disable (uncheck) 'Reassemble fragmented IP datagrams' option.
The option is available under Edit --> Preferences --> Protocols --> IPv4 window
With the option Reassemble fragmented IP datagrams' disabled, Wireshark will display a fragmented SIP message