On Wed, Dec 15, 2010 at 09:46:34PM +0000, Christopher Maynard wrote:

> The problem I have with this is that 3503 is registered to MPLS Echo 
> so that dissector shouldn't have to be changed to essentially become a 
> heuristic one to accommodate this port-stealing protocol.

I agree that it is annoying when applications developers and 
administrators disregard best practices and use whatever port they feel 
like.  However, I'm not suggesting that we make it a full heuristic 
dissector that doesn't have an assignment and looks at all packets.  
Instead, we can just make it a "new-style" dissector that does some 
quick verification that the payload looks right and if not, kick it back 
for Wireshark to try another dissector.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev@wireshark.org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

Reply via email to