Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5746] Wireshark not able to decode the PPP frame in a sflo

Date: Fri, 11 Mar 2011 17:41:31 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5746

Chris Maynard <christopher.maynard@xxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |FIXED

--- Comment #10 from Chris Maynard <christopher.maynard@xxxxxxxxx> 2011-03-11 17:41:30 PST ---
(In reply to comment #4)
> if it does mean both, ...

And that's the key, "if".  But does it mean both or not?  If it does, then it's
easy enough to differentiate them (assuming IANA never assigns a PPP protocol
field to 0xff03).

But I couldn't help wondering, since the sflow spec referenced previously is
nearly 7 years old, that maybe there is a newer version somewhere that assigns
a different protocol number to PPP in HDLC framing.  That doesn't appear to be
the case though, so I committed a change in revision 36177 to the sflow
dissector that should fix this.  If it turns out that there is another protocol
number, then it's easy enough to undo.  This change has been scheduled to be
back-ported to 1.4.5.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.