Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] decoding thru unencrypted VPN tunnel

From: Bill Fassler <bill.fassler@xxxxxxxxx>
Date: Tue, 13 Mar 2007 10:47:44 -0700 (PDT)
My last post on this subject wound up on the wrong forum, so I'd like to repost here.  My traffic is encapsulated in a VPN tunnel, when it is unencrypted I can see the start of the IP protocol 5 bytes into the payload. The first 5 bytes are overhead protocols for the tunnel itself (some form of PPP I believe).  In any event I could care less at this time about those 5 bytes and I don't even understand that protocol enough at the moment to dissect and decode it (nor am I interested).

If I could simply use "decode as - IP" and set an offset into the payload I would be happy. Guy seems to be persuading me to use the LUA interface, but I have not heard from Luis to hear his input. Also I have never used LUA or the LUA interface so I may need a little guidance if that is my only realistic option.

This is a back burner project for me now, but I want the capability in place before it becomes essential to my development/debug.

Thanks as always for your help.
Bill


No need to miss a message. Get email on-the-go
with Yahoo! Mail for Mobile. Get started.