Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] lwapp decode

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "mail.ag" <mail.ag@xxxxxxxxxxxxxxxxxxx>
Date: Fri, 03 Nov 2006 15:46:55 -0500

Greetings:

I'm having trouble decoding an LWAPP encapsulated packet.  Attached is a
capture file with two packets.  It was taken on the *wired* side of the
access point, not the RF side.

The two packets are an ICMP echo request and reply. 

Wireshark (Version 0.99.4 (SVN Rev 19757)) is calling the packet
malformed and decoding the ICMP payload (ACBDEFG....) has 802.11
Wireless LAN Management Frame Reserved Tags.

The 'Frame' Section of the decode indicates that the protocols in the
frame are eth:ip:udp:lwapp:wlan, but given that it is ICMP encapsulated
in LWAPP, should the list be eth:ip:udp:lwapp:icmp?

I tried forcing the decode as LWAPP-L3 which did not help.

This is a Circo Airespace 4.0.x setup.

Can Wireshark decode these types of LWAPP frames?

Thank you.

Attachment: lwapp-icmp.pcap
Description: Binary data

  • Prev by Date: Re: [Wireshark-users] multiple giop in one packet display last request_op in Info field...any way to change this?
  • Next by Date: Re: [Wireshark-users] SCSI RTP
  • Previous by thread: Re: [Wireshark-users] [Wireshark-dev] GTK+ 2.8.x and fonts
  • Next by thread: Re: [Wireshark-users] SCSI RTP
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation