Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5679] New: "Decode As" X.400 P1 or P3 not possible

Date: Fri, 11 Feb 2011 02:30:59 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5679

           Summary: "Decode As" X.400 P1 or P3 not possible
           Product: Wireshark
           Version: 1.5.x (Experimental)
          Platform: x86-64
        OS/Version: Windows XP
            Status: NEW
          Severity: Major
          Priority: Medium
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: joachim.koetzing@xxxxxxxxxxxx


Created an attachment (id=5933)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=5933)
wireshark capture showing the error

Build Information:
Version 1.5.0 (SVN Rev 35637 from /trunk)

Copyright 1998-2011 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with GTK+ 2.16.6, with GLib 2.24.2, with WinPcap (version
unknown), with libz 1.2.3, without POSIX capabilities, without libpcre, without
SMI, with c-ares 1.7.1, with Lua 5.1, without Python, with GnuTLS 2.8.5, with
Gcrypt 1.4.5, without Kerberos, with GeoIP, with PortAudio V19-devel (built Jan
24 2011), with AirPcap.

Running on Windows XP Professional x64 Edition Service Pack 2, build 3790, with
WinPcap version 4.1.2 (packet.dll version 4.1.0.2001), based on libpcap version
1.0 branch 1_0_rel0b (20091008), GnuTLS 2.8.5, Gcrypt 1.4.5, without AirPcap.

Built using Microsoft Visual C++ 9.0 build 30729

--
Data from an X.400 P1 or P3 connection are captured. If the capture starts
after the connection establishment, wireshark is not able to detect that this
is X.400 traffic, instead the traffic is analyzed with the PRES (ISO
presentation layer) dissector. I shall be possible to change this
classification with "Analyze->Decode As" but it is not possible.

The attached capture file shows two X.400 P1 connections, one with the
connection esatblishment inside and one outside the capture data.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.