Re: [Wireshark-users] Diameter AVPs of Cx and Sh interface

2007-11-30 Thread Anders Broman
Hi, Is the Vendor-bit set and the vendor id set to 3GPP? This AVP should be decoded by the upcoming 0.99.7 release and with that Libxml2 is no longer needed with it. http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.7pre2.exe Regards Anders -Ursprungligt meddelande- Från:

[Wireshark-users] Diameter AVPs of Cx and Sh interface

2007-11-30 Thread Franz Edler
Hi all, I need some help in decoding the Diameter AVPs of the Cx and Sh interface. - I have installed Wireshark 0.99.6a on my WindowsXP notebook. - I have also added libxml2.dll into the \Programme\Wireshark directory. - I also see imscxdx.xml and TGPPSh.xml in the \Programme\Wireshark\diameter di

Re: [Wireshark-users] FC Protocol ??

2007-11-30 Thread ronnie sahlberg
Fibre channel is a SAN protocol so it would be very likely that it would consume a lot of bandwidth. I.e. it is used to (primarily) act as a transport for SCSI Normally you would not see FC on the same segment as you would have ordinary traffic but rather only on dedicated networks in the data ce

Re: [Wireshark-users] docsis problems

2007-11-30 Thread Frank Bulk
Martin shared a copy with me and it didn't decode correctly in 0.99.5 rev 20677. Frank -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Guy Harris Sent: Friday, November 30, 2007 2:19 PM To: Community support list for Wireshark Subject: Re: [Wireshark-user

Re: [Wireshark-users] docsis problems

2007-11-30 Thread Guy Harris
[EMAIL PROTECTED] wrote: > any one knows why (newest version) Wireshark cant handle Docsis packets ? Can older versions handle them? > When i snif on my Cisco CMTS e.g. DHCP req. from a Cablemodem, i can only > see the ip-pack. from the server. > The rest packets are marked with : DOCSIS Mac spe

Re: [Wireshark-users] ***SPAM*** FC Protocol ??

2007-11-30 Thread Sake Blok
On Fri, Nov 30, 2007 at 01:47:38PM -0600, Daniel Koepke wrote: > > Is the MAC address in the scan validate or is it transposed or > deciphered correctly It mostly is, but that does not say there can't be a bug somewhere. > Can the FC protocal be run over ethernet or how should I view these scan

Re: [Wireshark-users] Saving/Printing Protocol Hierarchy Window

2007-11-30 Thread Sake Blok
On Thu, Nov 29, 2007 at 03:00:51PM -, Whiston, Gaetan wrote: > Hello - does anyone know how I can print or save to text file the > Protocol Hierachy window. > > I'd like to save the info for baseline reporting purposes. That functionality is not yet part of Wireshark, the only way to keep thi

Re: [Wireshark-users] WireShark SSL Encryption

2007-11-30 Thread Stephen Fisher
On Fri, Nov 30, 2007 at 07:40:07AM -0600, Ray Tompkins wrote: > Then a third file, when I open it looks very much like the > rsasnakeoil2.key that we used in WireShark University class. So I've > tried all three with no success. Here is a screen shot of how I have > it setup within WireShark. If

[Wireshark-users] WireShark SSL Encryption

2007-11-30 Thread Ray Tompkins
The packets are encrypted, so I'm using the Wireshark SSL to decode them. They have given me several files that they believe to be the SSL key. One file with a "cer" extension, one with a "pfx" extension. Then a third file, when I open it looks very much like the rsasnakeoil2.key that we used in Wi

[Wireshark-users] docsis problems

2007-11-30 Thread admin2
Hello, any one knows why (newest version) Wireshark cant handle Docsis packets ? When i snif on my Cisco CMTS e.g. DHCP req. from a Cablemodem, i can only see the ip-pack. from the server. The rest packets are marked with : DOCSIS Mac specific[malformed packet.] I can see that Wireshark supports