# impossibly large packets

**URL:** <https://community.zeek.org/t/impossibly-large-packets/2554>\
**Category:** Zeek\
**Created:** [February 11, 2013, 8:14pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554 "2013-02-11T20:14:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Ray](https://avatars.discourse-cdn.com/v4/letter/t/ce73a5/32.png) [@Tim\_Ray](https://community.zeek.org/u/Tim_Ray)\
**Post date:** [February 11, 2013, 8:14pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/1 "2013-02-11T20:14:45Z")

</div>

Does Bro have any way to handle corrupt packets that appear to be impossibly large? When we get those in our setup, it hangs. Thanks.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [February 11, 2013, 8:32pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/2 "2013-02-11T20:32:02Z")

</div>

You're going to have to define "impossibly large". Could you also describe more what you mean when you say it hangs too?  
  
Just a pre-guess though… Do you have any NIC features enabled for extended packet handling?  
&nbsp;&nbsp;[http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html](http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html)

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Tim\_Ray](https://avatars.discourse-cdn.com/v4/letter/t/ce73a5/32.png) [@Tim\_Ray](https://community.zeek.org/u/Tim_Ray)\
**Post date:** [February 11, 2013, 8:41pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/3 "2013-02-11T20:41:09Z")

</div>

Our current best guess is 1,766,926,155 bytes. That's clearly far above  
the jumbo limit, or any other limit I can think of. When we try to open  
that packet in Wireshark, it's corrupt, which I believe to be true.

How does Bro handle such a case? Does it understand that such a thing is  
corrupt?

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [February 11, 2013, 8:44pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/4 "2013-02-11T20:44:41Z")

</div>

How was this packet acquired? It sounds like you have a corrupted packet capture.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![William\_Jones](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@William\_Jones](https://community.zeek.org/u/William_Jones)\
**Post date:** [February 12, 2013, 4:24pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/5 "2013-02-12T16:24:09Z")

</div>

Most network adapters have LRO on by default. This can translate to large packets on bro input. If you running bro on linux you see this behavior.

---

<div class="post-metadata">

**Author:** ![Tim\_Ray](https://avatars.discourse-cdn.com/v4/letter/t/ce73a5/32.png) [@Tim\_Ray](https://community.zeek.org/u/Tim_Ray)\
**Post date:** [February 12, 2013, 5:27pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/6 "2013-02-12T17:27:48Z")

</div>

Most network adapters have LRO on by default. This can translate to large packets on bro input. If you running bro on linux you see this behavior.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/impossibly-large-packets/2554/7 "2022-05-06T15:40:46Z")

</div>


