Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] Re: Capture

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Thu, 24 Mar 2005 12:11:19 -0800
Alexandre Rafalovitch wrote:
I thought the easiest way was to find a packet for the HTTP trafic and
then 'decode as'/both/HTTP and Ethereal would redo the dissection?

That'll work as well, and will work in pre-0.10.10 releases.

It worked for me anyway. Was I missing some functionality by doing it that way?

None other than the ability to make "dissect traffic on port 6660 as HTTP" a permanent setting. "Decode As" changes the table that maps ports to dissectors; the HTTP dissector option causes the HTTP dissector to register itself in that table with that port, so they both affect the table.