Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Hex Stream Decode (SCCP)

From: "Luis EG Ontanon" <luis@xxxxxxxxxxx>
Date: Thu, 14 Aug 2008 16:26:19 +0200
No it isn't sscf-nni!

I see no potential MTP3 header (SI=3) followed by anything that can be
a valid SCCP message.

What protocol is supposed to be in there?
Are they more packets or just one?
Which are OPC and DPC? (to try to look for a valid routing label)



My sensation is that you are logging internal signals and these
contain no protocol data but an internal representation of it (unknown
to the most).

\Lego


On Thu, Aug 14, 2008 at 4:07 PM, Luis EG Ontanon <luis@xxxxxxxxxxx> wrote:
> The encapsulating protocol is sscf-nni (ATM, AAL5 and SSCOP were
> stripped already) so you need to:
>
> text2pcap -l 160 sccp.txt sccp.pcap
>
> Then you have to add to Protocols->DLT_USER->EncapsulationsTable an
> entry for  DLT=160 (USER12) to use  sscf-nni as payload protocol.
>
> --
> This information is top security. When you have read it, destroy yourself.
> -- Marshall McLuhan
>



-- 
This information is top security. When you have read it, destroy yourself.
-- Marshall McLuhan