SNGREP not capturing Fragmented packets
Hi kaian
As we could observe SNGREP is not capturing fragemented packets
Frame 9 and Frame 10 are fragmented packets but in frame 9 we could see no UDP or TCP layer. sngrep has no knowledge about port's when frame 9 is received so when frame 10 receives SNGREP couldn't prepand frame 9 to frame 10. How to overcome this issue.
Hi!
Can this reproduced while reading from a PCAP file? Could yo provide a PCAP file to debug this fragmentation issue?
Thanks in advance!
Hi kaian i have attached you the pcap file full_tcpdump_file.zip
Hi @sajai20
Thanks a lot for the testing PCAP!!
Without debugging the packets, the flow seems identical from wireshark and sngrep 1.8.2
What is the missing fragmented packet sngrep has not captured?
Best regards!!