Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] DAG 3.7T card SS7 capture

From: "DROUIN FLORENT" <Florent.Drouin@xxxxxxxxxxxxxxxxx>
Date: Wed, 14 May 2008 17:18:49 +0200
Could you send a capture done with libpcap, and an other one taken with dagsnap, so I can check both.
Could you check too, the value of the environment variable  ERF_FCS_BITS ( should be set to 0)

-----Message d'origine-----
De : wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] De la part de B.Tosovsky
Envoyé : mercredi 14 mai 2008 16:57
Cc : wireshark-users@xxxxxxxxxxxxx
Objet : Re: [Wireshark-users] DAG 3.7T card SS7 capture

Yes, mtp3 layer is decoded correctly- ITU-T, I see proper SPCs. Also i see proper GT numbers and SSN, but after Calling GT number  i see malfolrmed packet...
When i load ERF file, everythig is decoded correctly.

> ------------ Původní zpráva ------------
> Od: B.Tosovsky <B.Tosovsky@xxxxxxxxx>
> Předmět: Re:DAG 3.7T card SS7 capture
> Datum: 14.5.2008 16:41:30
> ----------------------------------------
> Thank you for the response. I have partial succes. I changed link type 
> to ss7 and now i see proper mtp3 layer messages, but sccp layer 
> packets are malformed either as mtp2 layer packets  (FISU ???). Is it 
> possible packets are somewhere cutted ?
> I use latest stable wireshark 1.0.0 version and libpcap 0.9.8.
> 
> Thanks B.  
> > ------------ Původní zpráva ------------
> > Od: B.Tosovsky <B.Tosovsky@xxxxxxxxx>
> > Předmět: DAG 3.7T card SS7 captur
> > Datum: 14.5.2008 15:27:03
> > ----------------------------------------
> > Hello,
> > 
> > can you please help. I am playing with this card in Debian. Card is 
> > properly installed, libpcap was compiled with DAG support.
> > 
> > If i try to capture mtp2 packets  with endace tool dagsnap and save 
> > in ERF format I a can read this file offline in wireshark properly.
> > 
> > But if i try to capture packets  directly in wireshark through new 
> > interface dag0  I see capturing packets, but there are decoded as 
> > CISCO HDLC malformed packets ???
> > 
> > Same situation is if i try to convert ERF file with dagconvert tool 
> > to pcap file.
> > 
> > Thanks
> > 
> > B. 
> > 
> > 
> 
> 
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users