In the IP, TCP or UDP headers is the "Checksum" field, which has two parts to it. For the IP checksum this is:-
Header checksum: 0xbbd5 [correct] [Good: True] [Bad : False] with similar for the TCP and UDP checksums. Is there any difference from a logical point of view when using a display filter to find packets with bad IP checksums between these two expressions:- ip.checksum_bad == 1 or ip.checksum_good == 0 As a checksum can only be correct or bad, surely both of these filters are the same?
_______________________________________________ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users