Skip to content

tcpdump cuts off header options #209

@tflach

Description

@tflach

For packet captures, the capture length is currently set to a size that cuts off almost all TCP header options. When analyzing traces it is very useful to be able to see SACK blocks. In older traces at least the first SACK block was still captured, however since many connections now have timestamps enabled SACKs are pushed further out in the header, and they are no longer captured at all.

It would be very beneficial to use a mechanism that does not truncate header options. I am aware that header length is dynamic, so maybe there is a way to sanitize traces after capturing while extending capture length to make sure that headers are always completely captured?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions