Skip to content

IPv4 头字段 ​

📋 r0capture 造的 pcap 包里 IPv4 头(20 字节)每个字段。

IPv4 头结构 ​

log_pcap 写的 IPv4 头:

python
# --- IPv4 头 20字节, 大端序 ---
(">B", 0x45),               # Version + IHL
(">B", 0),                  # Type of Service
(">H", 40 + len(data)),     # Total Length
(">H", 0),                  # Identification
(">H", 0x4000),             # Flags + Fragment Offset
(">B", 0xFF),               # TTL
(">B", 6),                  # Protocol
(">H", 0),                  # Header Checksum
(">I", src_addr),           # Source Address
(">I", dst_addr),           # Destination Address

字段详解 ​

偏移长度格式值含义
01>B0x45Version(4) + IHL(5)
11>B0Type of Service / DSCP
22>H40+lenTotal Length(整个 IP 包长)
42>H0Identification(分片标识)
62>H0x4000Flags(DF) + Fragment Offset
81>B0xFFTTL(255 跳)
91>B6Protocol(6=TCP)
102>H0Header Checksum
124>Isrc_addrSource Address
164>Idst_addrDestination Address

关键字段 ​

Version + IHL: 0x45 ​

  • 高 4 位 4 = IPv4
  • 低 4 位 5 = IHL(Internet Header Length),单位 4 字节,5×4=20 字节头

二进制 0100 0101 = 0x45。

Flags: 0x4000 ​

  • 0x4000 二进制 0100 0000 0000 0000
  • DF(Don't Fragment)位置 1,不分片

Protocol: 6 ​

值协议
1ICMP
6TCP ← r0capture 用
17UDP

Checksum: 0 ​

填 0——Wireshark 不校验造的包也能解析,省去计算校验和的麻烦。

字节序 ​

IPv4 头按网络协议规定用大端序(网络序,>)。详见 字节序。

相关文档 ​

基于 VitePress 构建 · 教学用途