You must create a packet header for every fragment packet. The following table describes the packet header for fragmented packets.
Bytes | Value | Comment |
|---|---|---|
4 | creationTime | It is the "creationTime" from the table. |
4 | TimeStamp | Microseconds. |
4 | len + 14 | Packet log data length (blob length) + 14 |
4 | len + 14 | Packet log data length (blob length) + 14 |
6 | sourceAddr | 0xFFFFFFFFFFFF if it is 0: Got it from step 4 |
6 | targetAddr | 0xFFFFFFFFFFFF if it is 0: Got it from step 4 |
2 | 0xFFFF | IP type |
n | Packets | Actual packet log data. |