Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] Decoding problem in ANSI MAP messages

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Sanjay Nayak <sanjay.nayak.bdk@xxxxxxxxx>
Date: Wed, 1 Apr 2009 18:18:43 +0530

Hello

I want to decode the ANSI MAP Authentication Failure Report message in
the latest wireshark.



According to the section 2.4 of the spec.

http://www.3gpp2.org/Public_html/specs/X.S0004-540-E_v2.0_070723.pdf

Here there are seven mandatory parameters for the message
Authentication Failure Report.

1. Electronic serial number
2. MSID(i.e MIN/IMSI)
3.Report Type
4.System Access Type
5.System Capabilities(Serving)

That i have already given in my message.

But here for the parameter MSID,
if i give IMSI instead of MIN. Then it shows
BER Error: Unknown field in SET class:CONTEXT(2) tag:242.

Also it shows two tag errors at the last

1.BER Error: Missing field in SET class:CONTEXT(2) tag:8 expected
2.BER Error: Missing field in SET class:CONTEXT(2) tag:44 expected


That means it  considers two extra parameters as mandatory. Plz
suggest what is the problem with it?

For parameters the spec is

http://www.3gpp2.org/Public_html/specs/X.S0004-550-E_v2.0_070723.pdf


Regd's
Sanjay

  • Follow-Ups:
    • Re: [Wireshark-users] Decoding problem in ANSI MAP messages
      • From: Anders Broman
  • Prev by Date: [Wireshark-users] filtering on Ethernet MAC OUI
  • Next by Date: Re: [Wireshark-users] Decoding problem in ANSI MAP messages
  • Previous by thread: Re: [Wireshark-users] filtering on Ethernet MAC OUI
  • Next by thread: Re: [Wireshark-users] Decoding problem in ANSI MAP messages
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation