[Winpcap-users] for TCP session monitoring is it possible to avoid receiving fragmented IP packets by using an appropriate pcap filter?

Jerry W. Rice jerrywrice at fabnexus.com
Sat Sep 22 14:06:19 PDT 2012


I'm implementing a monitoring application that tracks a specific TCP
session.  I know in advance the socket's source and destination IP addresses
and port numbers.  Will an appropriately defined 'pcap filter' eliminate the
possibility of receiving fragmented IP packets with get_next_ex() in my
application?  If so, a suggested filter string would be greatly appreciated.

 

JWR

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.winpcap.org/pipermail/winpcap-users/attachments/20120922/586c7ea6/attachment.html>


More information about the Winpcap-users mailing list