Sunday, January 21, 2018

If I run wireshark on both ends of a link, and I don't see IP fragments, can I be 100% certain there is no fragmentation along the path?

Just like the title says. Got a tech somewhere screaming fragmentation is the issue, however I am sure it isnt because...

  1. PMTUD is working and because i get back ICMp type 3 code 4
  2. Hosts agree on a low TCP MSS, lower than the path MTU and the traffic is TCP
  3. When I capture on SRC and DSt I don't see any IP fragments

All my labs say I am correct, but ya know how it is on these email threads, I want to be 100% before I say something... So do you agree that if I run wireshark on the SRC and DST and I don't see IP fragments for a particular TCP flow, then I can be sure that it is not being fragmented.



No comments:

Post a Comment