Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 4721] New: Want to be able to apply decode as to Data Port

Date: Wed, 28 Apr 2010 08:41:29 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4721

           Summary: Want to be able to apply decode as to Data Portion of
                    Lan Trace
           Product: Wireshark
           Version: 1.3.x (Experimental)
          Platform: x86
        OS/Version: Windows XP
            Status: NEW
          Severity: Normal
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: gsearle@xxxxxxxxxx


Created an attachment (id=4585)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=4585)
Trace with corrupted mac header

Build Information:
Version 1.3.4 (SVN Rev 32342 from /trunk)
--
I get LAN traces from time to time that have a corrupted MAC header.  The
header is only corrupted in the trace and the actual packet that was on the
wire had a valid MAC Header.  This only happens on newer 10GB LAN adapter when
we take a trace from the server.

What I would like to be able to do is disable protocol resolution up to
Ethernet then do a decode as IP the Data from that point.

Decode as is grayed out and does not allow this.

I have attached a trace that shows this behavior.  In packet 1 you will see
that the Ethernet Type Field is 0000.  This should be 0800.  Is there anyway to
force this to be 0800?

Thanks,

Greg Searle

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.