Hello all. Recently looking at some pcaps of a connectivity issue and noticed numerous packets >1500 bytes. This was a connection from a server on the Internet to a user behind a home wi-fi router. My experience tells me IP Packets received should all be <1500bytes or so when they are coming from the internet.
I know Wireshark can sometimes show larger TCP segments if they are being offloaded to the NIC for fragmentation but this is *received* traffic, and from the Internet.
Can someone please help me understand how this works?
No comments:
Post a Comment