ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] ISDN Layer 3 decode

From: "Keith French" <keithfrench@xxxxxxxxxxxxx>
Date: Fri, 28 Oct 2011 19:32:08 +0100
I think the two attachments should be self explanatory with the notes I have added to the bug:-

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6483



-----Original Message----- From: Guy Harris
Sent: Friday, October 28, 2011 4:16 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] ISDN Layer 3 decode


On Oct 27, 2011, at 7:34 AM, Keith French wrote:

There still is a slight problem. If the trace starts with a series of layer 2
receive ready frames, you get one of these two errors:-

The problem has nothing to do with RR frames; it has to do with the length of the first record in the file - if it's 8 bytes long, it gets ignored by Wireshark (even if it's a packet record), and if it's not 8 bytes long, Wireshark gets very confused because it starts looking for records in the middle of a record.

I've checked in a fix in revision 39645. See whether that works with the other captures (and look at bug 6483 - I've asked for some more information to see if I can guess what the first 8-byte record is in the other two .aps files).
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe