Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5898] Netflow dissection stops prematurely

Date: Sun, 8 May 2011 01:58:25 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5898

Marco <marcodome@xxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |FIXED

--- Comment #2 from Marco <marcodome@xxxxxxxxx> 2011-05-08 01:58:01 PDT ---
(In reply to comment #1)
> Can you try prerelease r37013 to see if it fixes the bug? It should be
> available at 
> 
>     http://www.wireshark.org/download/prerelease/
> 
> in the next hour or so. If it doesn't fix the bug, can you upload a capture
> file that demonstrates the problem?

It works!!!
Thanks!

Marco

ps: I didn't add an attachment because I didn't find a trivial way, working on
a mac, to anonymize the content of netflow capture...

pps: I have an "additional question" (I don't know what is the desidered
working flow): because the NetFlow v9 needs a template to be understood, and
the template it's another Netflow packet, when I open a dump Wireshark says
"Data (160 bytes), no template found" until I don't scroll down and I find a
template packet (and when I find it, Wireshark shows the details also  of the
previous packets.
Is there any way to say wireshark to read forward the dump looking for the
template, so that I don't have to manually find it?
If it makes sense, I can write in a new bug or a wish.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.