Hexadecimal Code interpretation of Fragment offset (fragment offset) Field in packet Analysis
Learning packet analysis encountered as described in the confusion, GOOGLE& whiteness failed. After reading the description of the fragment offset field in RFC791, I can only understand it after thinking and calculation. I hope it will be helpful to children's shoes who have the same confusion. The following starts with the screenshot:
As shown in the picture, the hexadecimal code corresponding to the gray bottom Fragment offset:1480 line is the blue background 0X20b9. At first, I wonder why the decimal 1480 corresponds to the 0x20b6. No matter how wrong it is, I don't know if the reader has encountered such a doubt!
Refer to the description of the relevant field in RFC791 to understand that this 1480 refers to the actual byte of the offset rather than the decimal value corresponding to the bit in the fragment offset field. This field is based on eight "octets", so the value of 1480 in this field is divided by 8, which translates to 0 0000 1011 1001 in binary, because there is a 3-bit Flag field with a value of 0000, so the binary value is 0010 0000 1011 1001 after adding the Flag field, which translates into binary is 20b9. Please do the math for yourself. If you don't understand, you need to master the structure and base of the data packet first.