Tracking sequence numbers and flags in Wireshark

Tracking sequence numbers and flags in Wireshark

One of the things I learned a while back was a really good tip when using Wireshark. I find people sometimes get tied up tracking the sequence numbers and the wireless frame flags in Wireshark.

Having to open the frames and look for flags and following sequence numbers can be quite complex and time consuming.

Here’s a Wireshark Tip

Here is a little tip I learned, which seems so obvious once someone tells you…

When viewing the frames in Wireshark, the “Info” column can be very informative. It shows the type of frame, and the sequence number (SN). It also shows the SSID name, the Beacon Interval (BI) and also the Flags from the wireless frame header.

One exception to this standard “info” field display is, if you have data that is not encrypted, Wireshark may start to show you the TCP/UDP or HTTP information in the “info” field, then you do have to go and dig, and look inside the frame to see the flag details. Basically, on an unencrypted Wireless network, or if you have entered the PSK intentionally so as you can decrypt packets, this may display actual packet data, not “useful wifi info”.

If we take a look in Diagram 1 below, you will see the Flags are listed underneath the “Flags” section within the “Frame Control Field”. You can also find a summary right next to the “IEEE 802.11 Beacon Frame” section (in fact whatever the type of frame you are viewing, the flags are summarized next to this section). A feature that often goes unnoticed, they are also summarized in the top right section of the Wireshark Frames display, within the “info” field.

 

DIAGRAM 1

 

When the flags are shown next to the “IEEE 802.11 Frame” field (where represents the type of frame shown) or when show within the “info” column, the frame flags are listed using the following format: xxxxxxxxC, where the x’s represent characters that are displayed. The format is displayed as a mix of eight letters followed by an uppercase “C”. If a given flag is not set, it is represented as a period. As you can see in Diagram 1, none of the flags are set, and so the flag field will be represented as eight periods followed by an uppercase “C”.

The eight flags are shown as the following letters in this order: opmPRMFTC

o is the Order bit
p is the protected bit
m is the More Data bit
P is Power Management
R is Retry
M is More Fragments
F is FromDS
T is ToDS

That’s the eight flags!

Well, what’s the “C” then, I hear you ask.

A lot of people misunderstand this, and mis-name this uppercase “C”.

The “C” is there as long as the frame did not fail its CRC check. Now please note this is not the same as the frame passing its CRC check. If for whatever reason the CRC is not present (maybe because you only captured a small segment of the frame e.g. 128B, or you didn’t capture FCS’), Wireshark represents this with an uppercase “C”. This happens whether the frame is corrupt or not and can be quite confusing. So, watch out for that one!

2025 Update...

We talk about this, more, in our AMA series webinars:

https://www.youtube.com/watch?v=TM70jXEsFsk


That’s it for this month. See you next time.

If you are looking to make your mark in the IT Industry, then NC-Expert offers excellent training courses aimed at relevant IT industry certifications – contact us today to get started.

NC-Expert Blog

By Rie Morgan July 23, 2026
Few phrases trigger a knowing smile from experienced Wi-Fi engineers quite like this one, "It's the client's fault." Someone's video call drops while walking through the office or a warehouse scanner pauses between aisles, voice handsets crackle as users move from one floor to another... then, almost immediately, someone points at the device and confidently declares, "Well... clients decide when to roam." Technically, they're correct. But, practically, that's only part of the story. Roaming is one of the most fascinating aspects of Wi-Fi because it isn't controlled by a single device or a single setting. It's a partnership between the client, the infrastructure, and the RF environment. When that partnership breaks down, blaming one side rarely tells the whole story. Let's bust another myth... Yes, Clients Make the Decision Let's start with the important truth: in almost every Wi-Fi deployment, the client device ultimately decides when to leave one AP and join another. Laptops, smartphones, tablets, barcode scanners, medical devices, and countless IoT products all use their own roaming algorithms. Some roam aggressively whereas some cling to their current AP for far too long. Others seem convinced that losing the connection entirely is preferable to switching. Every Wi-Fi engineer has encountered at least one stubborn client that appears almost “emotionally attached” to a particular AP. :) Client behavior matters, but that's not where the story ends.
By Rie Morgan July 17, 2026
Every Wi-Fi engineer has heard some version of it, "Can't we just install the access points where the old ones were?" Or perhaps, "The floorplan looks straightforward. Let's save some time and skip the survey." Occasionally, someone even says the dangerous words, "We've done hundreds of these buildings. They're all basically the same." That's usually the point where experienced wireless engineers quietly smile, knowing that the building is about to teach everyone a valuable lesson because: buildings don't read design guides, concrete doesn't care about your deployment schedule, metal doesn't respect your project budget, and radio waves have never once agreed to cooperate, simply because everyone wanted them to. Let's talk about why a site survey isn't an optional luxury... it's one of the most valuable engineering tools available. Every Building Is Different At first glance, two office buildings may appear identical: same square footage, same number of floors, similar room layouts, yet their wireless behavior can be dramatically different: one may have reinforced concrete walls, another may contain extensive glass partitions, the warehouse may be filled with moving inventory, a hospital may have elevators, imaging equipment, and countless reflective surfaces, a manufacturing facility may contain machinery that wasn't mentioned on any floorplan, and remember: even furniture changes RF behavior! Anyone who has performed enough surveys eventually develops a healthy respect for one simple fact: the building always gets a vote, too!
By Rie Morgan July 13, 2026
There is something wonderfully satisfying about seeing a Wi-Fi channel get wider: twenty megahertz becomes forty. Forty becomes eighty. Eighty becomes one hundred and sixty. This begs the question: more bandwidth must mean more speed... right? Well... sometimes. Like many things in Wi-Fi engineering, the answer begins with, "It depends." The idea that wider channels always deliver better performance has become surprisingly common. It's an understandable conclusion because, in theory, wider channels can carry more data. More lanes on a highway should allow more traffic to flow. But Wi-Fi isn't driven by theory alone. The RF environment has an annoying habit of reminding us that physics always gets the final vote. Let's explore why bigger isn't always better... More Lanes... But Fewer Roads Imagine a city with only a handful of highways. If you combine four lanes into one giant superhighway, each individual vehicle might travel faster. Unfortunately, you've also eliminated several independent routes that other drivers could have used. That's exactly what happens with channel bonding: - An 80 MHz channel occupies the same spectrum as four adjacent 20 MHz channels. - A 160 MHz channel consumes eight. While you've increased the potential throughput available to one transmission, you've dramatically reduced the number of separate channels available for everyone else. In an empty environment, this is often perfectly acceptable. But, in a busy enterprise? Not so much.