This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I'm capturing on a linux server using tcpdump

tcpdump -i eth2 -s 1600 -w file.out

When reviewing the file.out in Wireshark I see many frames that are huge (larger than 9K bytes). These ethernet frames aren't valid on the network. I'm not using jumbo frames either and they are larger than 9K.

Our theory is the huge ethernet frames are not "real" but are the OS transferring to the 10Gbe nic driver.

Any thoughts or experience with these ?

thanks Tim

asked 01 Mar '12, 11:09

timc's gravatar image

timc
1111
accept rate: 0%


Correct: you're probably looking at Segmentation Offload.

[Update] Don't forget to drop by and Accept this answer if it answered your question.

permanent link

answered 01 Mar '12, 11:47

JeffMorriss's gravatar image

JeffMorriss ♦
6.2k572
accept rate: 27%

edited 09 Mar '12, 06:58

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×87
×41
×6

question asked: 01 Mar '12, 11:09

question was seen: 3,971 times

last updated: 09 Mar '12, 06:58

p​o​w​e​r​e​d by O​S​Q​A