Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: Re: [Wireshark-dev] How to parse PDCP packet?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Siva.S" <s.siva@xxxxxxxxxxxxx>
Date: Tue, 06 Jan 2009 20:22:31 +0530

Hi,
    Thank you very much for your response.
    (2) when dissecting RRC, record the config of the channels and look it up in the MAC/RLC/PDCP dissectors.
   
How can we record the config of the channels without dissecting the other layers?. Whether the RRC coming on CCCH have those information?(i.e. RRC Connection Setup)?.

Thanks & Regards,
Siva.S

Martin Mathieson wrote:


On Tue, Jan 6, 2009 at 5:20 AM, Siva.S <s.siva@xxxxxxxxxxxxx> wrote:
Hi,

   Anyone finished parsing for PDCP?. How to identify whether the PDCP
packet was having a 5-bit Sequence No or a 7-bit or 12-bit?.
   Likewise, I want to know for RLC too. Whether, it's UM mode or AM
mode or TM mode.
   Can anyone help me in this?

My PDCP dissector completely dissects the PDCP header.  That part was fairly simple, what took up time and lines of code was the ROHC which still isn't where I wanted it to be.  I know that at least one other person has been working on a PDCP dissector.  Hopefully one of our dissectors, or a merged version can be checked in soon.

To get the information you mention above you either need:
(1) to get it from the file (which I'm doing)    OR
(2) when dissecting RRC, record the config of the channels and look it up in the MAC/RLC/PDCP dissectors.

I know there is interest in doing (2).  You would still need to be able to work out at least:
- for MAC, whether a frame was uplink or downlink, and which RNTI (or at least type of RNTI) was the frame sent from/to in order to decode it properly
- for PDCP, which channel a given frame is on.  And if you want to decode the ROHC headers, you'll also need to somehow know:
      - the mode (U, O, R)
      - whether the IP identifiers were sequential or not for ROHC (i.e. the RND variable).

Martin
 


Thanks & Regards,
Siva.S
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
            mailto:wireshark-dev-request@xxxxxxxxxxxxx?subject=unsubscribe


___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev@xxxxxxxxxxxxx> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request@xxxxxxxxxxxxx?subject=unsubscribe
  • References:
    • [Wireshark-dev] How to parse PDCP packet?
      • From: Siva.S
    • Re: [Wireshark-dev] How to parse PDCP packet?
      • From: Martin Mathieson
  • Prev by Date: Re: [Wireshark-dev] Package issue under Windows XP
  • Next by Date: [Wireshark-dev] buildbot failure in Wireshark (development) on Windows-XP-x86
  • Previous by thread: Re: [Wireshark-dev] How to parse PDCP packet?
  • Next by thread: Re: [Wireshark-dev] FAQ still causing trouble (make rpm-package)
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation