wireshark-users May 2011 archive
Main Archive Page > Month Archives  > wireshark-users archives
wireshark-users: Re: [Wireshark-users] How does wireshark identi

Re: [Wireshark-users] How does wireshark identify tcp streams?

From: Guy Harris <guy_at_nospam>
Date: Sat May 21 2011 - 18:15:29 GMT
To: Community support list for Wireshark <wireshark-users@wireshark.org>

On May 21, 2011, at 11:12 AM, Irfan Habib wrote:

> Wireshark assigns numbers to tcp streams in a pcap file and packets can be filtered based on that tcp stream number. My question is, what properties in a packet does wireshark use to determine which tcp stream it is part of?

Source and destination IP addresses and TCP port numbers.
___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@wireshark.org>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@wireshark.org?subject=unsubscribe