This is our old Q&A Site. Please post any new questions and answers at

For the same packet within the same PCAP file, By using different version of Wireshark tool, I can see different log view. Issue is not seen on Wireshark Version 1.10.0 but seen on recent version such as latest 2.0.1


// Wireshark Version 2.0.1

20 24.0 DTE DCE 0x002d 12 PPP Van Jacobson Compressed TCP/IP (0x002d)

// Wireshark Version 1.10.0, this is good

20 2016-02-17 10:01:18.6 12 TCP 35075 > hbci [PSH, ACK] Seq=1 Ack=1 Win=16384 [TCP CHECKSUM INCORRECT] Len=7

Can you please let me know if there is any settings relate to this.

I checked Edit -> Preference -> Protocols -> PPP, <decompressed vj-compressed="" frames=""> is already checked

asked 17 Feb '16, 21:46

stephennnuaa's gravatar image

accept rate: 0%

edited 17 Feb '16, 21:47

Please file a bug on the Wireshark Bugzilla and attach the capture to the file.

permanent link

answered 18 Feb '16, 00:24

Guy%20Harris's gravatar image

Guy Harris ♦♦
accept rate: 19%

Thanks Harris, I will file the bug report shortly

(18 Feb '16, 01:26) stephennnuaa

The code to handle Van Jacobson compression was removed from Wireshark, starting with the 1.12 release, due to concerns about its license. See bug 12138.

permanent link

answered 18 Feb '16, 05:23

Guy%20Harris's gravatar image

Guy Harris ♦♦
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 17 Feb '16, 21:46

question was seen: 1,429 times

last updated: 18 Feb '16, 05:23

p​o​w​e​r​e​d by O​S​Q​A