EnablePacketFragmentCache

Since 3.6.1

Available since: Windows Packet Filter 3.6.1

The EnablePacketFragmentCache function activates IP packet fragment tracking in the kernel driver. When enabled, non-initial IP fragments (offset > 0) that lack transport layer headers are associated with their initial fragment, allowing static transport-layer filter rules (TCP/UDP/ICMP) to match all fragments of a packet flow correctly.

Syntax

BOOL WINAPI EnablePacketFragmentCache(
    _In_ HANDLE hOpen
);

Parameters

hOpen
[in] Filter device driver handle returned by OpenFilterDriver.

Return Value

Returns TRUE if fragment caching was enabled; otherwise returns FALSE.

Remarks

This function issues IOCTL_NDISRD_SET_FRAGMENT_CACHE_STATE with state TRUE to ndisrd.sys. Fragment tracking is critical when deploying stateful firewall or transport-layer filtering rules where fragmented traffic must not bypass transport filters.

See Also

DisablePacketFragmentCache, EnablePacketFilterCache