find same packet in wireshark

How to find the same packet in wireshark?

I want to take a capture simultaneously on a client and a server and I want to match a packet that left the workstation and went to the server.

I filter for the same source and destination ip address and tcp ports and the seq and ack numbers match but I find multiple packets on the server that match all the same values as the packet that left the workstation.

Is there some value that makes a packet unique?

Thanks
Dragon0x40Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

bbaoIT ConsultantCommented:
Eevery single IP packet has an Identification field. "When an IP packet is sent by the source, it places a unique value in the Identification field." You may find the ID field from every packet captured by WireShark.

TCP/IP Core Protocols
http://technet.microsoft.com/en-us/library/cc958827.aspx
0
Dragon0x40Author Commented:
the packet from the client has an ip identification field of 0x84de and if I right click on that and choose prepare filter for selected it creates a display filter of ip.id==0x84de and then I put that same display filter into the server capture

In the server capture using the identification field as a display filter does seem to narrow the search down but when i filter for ip.id==0x84de for example I get multiple packets (24 in this capture) and not even the same source and destination ip addresses.

if on the server I filter for the ip.id==0x84de plus the source and destination ports that narrows it down to a single packet. for example: ((ip.id==0x84de) && (tcp.src.port==1123)) && (tcp.dstport==443)

so it seems the identification field value gets reused and is not enough in a large packet capture to match up the packet that was sent from the client to the server and additional filter fields are necessary

The identification field does seem to work but is there an easier way?
0
Dragon0x40Author Commented:
http://www.experts-exchange.com/Programming/Languages/Pascal/Delphi/Q_21053894.html

Check this site: http://www.erg.abdn.ac.uk/users/gorry/course/inet-pages/ip-packet.html
The Identifcation field is a "16-bit number which together with the source address uniquely identifies this packet - used during reassembly of fragmented  datagrams" In other words ... this is an unique identifier to your packet ...

(Looks like a wireshark display filter in the form of (ip.id == 0x0d0e) && (ip.src == 192.168.1.67) should let me trace a specific packet anywhere in the network up until the private ip address gets translated to a routable address.)
0
bbaoIT ConsultantCommented:
good findings, well done.

> The identification field does seem to work but is there an easier way?

on the gateway server, you have to combine at least source IP as the criteria to uniquely locate a packet.

> Looks like a wireshark display filter in the form of (ip.id == 0x0d0e) && (ip.src == 192.168.1.67) should let me trace a specific packet anywhere in the network up until the private ip address gets translated to a routable address.)

yes and yes.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
TCP/IP

From novice to tech pro — start learning today.