Available since: Windows Packet Filter 3.6.1
The EnablePacketFragmentCache function activates IP packet fragment tracking in the kernel driver. When enabled, non-initial IP fragments (offset > 0) that lack transport layer headers are associated with their initial fragment, allowing static transport-layer filter rules (TCP/UDP/ICMP) to match all fragments of a packet flow correctly.
Syntax
BOOL WINAPI EnablePacketFragmentCache(
_In_ HANDLE hOpen
);
Parameters
hOpen
[in] Filter device driver handle returned by OpenFilterDriver.
Return Value
Returns TRUE if fragment caching was enabled; otherwise returns FALSE.
Remarks
This function issues IOCTL_NDISRD_SET_FRAGMENT_CACHE_STATE with state TRUE to ndisrd.sys. Fragment tracking is critical when deploying stateful firewall or transport-layer filtering rules where fragmented traffic must not bypass transport filters.