Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Display Filter Reference: TCP Encapsulation of IPsec Packets

Protocol field name: tcpencap
Versions: 1.0.0 to 1.6.5

Back to Display Filter Reference

Field name Type Description Versions
tcpencap.espzero Unsigned integer, 2 bytes ESP zero 1.0.0 to 1.6.5
tcpencap.ikedirection Unsigned integer, 2 bytes ISAKMP traffic direction 1.0.0 to 1.6.5
tcpencap.magic Sequence of bytes Magic number 1.0.0 to 1.6.5
tcpencap.magic2 Sequence of bytes Magic 2 1.0.0 to 1.6.5
tcpencap.proto Unsigned integer, 1 byte Protocol 1.0.0 to 1.6.5
tcpencap.seq Unsigned integer, 2 bytes Sequence number 1.0.0 to 1.6.5
tcpencap.unknown Sequence of bytes Unknown trailer 1.0.0 to 1.6.5
tcpencap.zero Sequence of bytes All zero 1.0.0 to 1.6.5

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation