hi, if I use this filter for example. if I get 2 segment from one ip, on first segment the syn flag=1, ack flag=0, on second segment syn flag=0 , ack flag=1 if I use this filter I need to see those 2 segment? or nothing? thanks asked 01 Jun '16, 20:56 dvir1999 edited 01 Jun '16, 21:58 sindy |
One Answer:
I may have got your question wrong, but: the display filter is evaluated for each packet (frame) separately, not for a set of packets related together (such as a UDP stream or a TCP session). So in your example, you'd see the first "segment" (which matches your filter example), but not the second one. answered 01 Jun '16, 21:57 sindy edited 01 Jun '16, 22:05 |