Display Filter Reference: Encapsulating Security Payload

Protocol field name: esp

Versions: 1.0.0 to 2.6.3

Back to Display Filter Reference

Field name Description Type Versions
esp.authentication_data Authentication Data Sequence of bytes 2.0.0 to 2.6.3
esp.icv_bad Bad Boolean 1.10.0 to 2.6.3
esp.icv_good Good Boolean 1.10.0 to 2.6.3
esp.iv ESP IV Sequence of bytes 1.0.0 to 2.6.3
esp.pad Pad Sequence of bytes 2.0.0 to 2.6.3
esp.pad_len ESP Pad Length Unsigned integer, 1 byte 1.0.0 to 2.6.3
esp.protocol ESP Next Header Unsigned integer, 1 byte 1.0.0 to 2.6.3
esp.sequence ESP Sequence Unsigned integer, 4 bytes 1.0.0 to 2.6.3
esp.sequence-analysis.expected-sn Expected SN Unsigned integer, 4 bytes 2.0.0 to 2.6.3
esp.sequence-analysis.previous-frame Previous Frame Frame number 2.0.0 to 2.6.3
esp.sequence-analysis.wrong-sequence-number Wrong Sequence Number Label 2.0.0 to 2.6.3
esp.spi ESP SPI Unsigned integer, 4 bytes 1.0.0 to 2.6.3
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More