ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-dev: RE: [Ethereal-dev] New dissector: packet-retix-bpdu.c

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Giles Scott" <gscott@xxxxxxxxxxxxxxxxx>
Date: Wed, 2 Mar 2005 01:40:21 -0800
Hi,

I guess we could check the destination address to see if it matches;
08:00:90:10:88:4a

Not sure where that check should go?

Cheers

Giles


-----Original Message-----
From: ethereal-dev-bounces@xxxxxxxxxxxx
[mailto:ethereal-dev-bounces@xxxxxxxxxxxx] On Behalf Of Guy Harris
Sent: Tuesday, March 01, 2005 9:59 PM
To: Ethereal development
Subject: Re: [Ethereal-dev] New dissector: packet-retix-bpdu.c

Giles Scott wrote:

> I came across a packet trace with Retix spanning tree packets in it.
> So here is a quick hack at a dissector for it.
> Several fields are not decoded but maybe someone knows what they are?
> 
> It uses llc.dsap && llc.ssap == 0x80,

Those are listed as "XNS" - and I've seen a capture with Token Ring 
packets with those DSAP and LSAP values containing what appears to be 
SMB traffic - perhaps some SMB-over-IPX variant?

Perhaps there's some way to distinguish between those two?

_______________________________________________
Ethereal-dev mailing list
Ethereal-dev@xxxxxxxxxxxx
http://www.ethereal.com/mailman/listinfo/ethereal-dev