Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 3410] SCTP SCCP: TCAP is not decoded

Date: Wed, 15 Apr 2009 06:12:04 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3410





--- Comment #3 from Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>  2009-04-15 06:12:03 PDT ---
(In reply to comment #2)
> Created an attachment (id=2937)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2937) [details]
> Pcap capture file of a packet with M3ua,sccp,tcap

This bug is talking about not dissecting TCAP but you changed the description
of the attachment to talk about RANAP.  Which is it (what is the SCCP payload
supposed to be: TCAP or RANAP)?

The capture file itself contains an SCCP Class-2 message (a DT1) so I suppose
it's supposed to be RANAP.

To explain the problem: in order to dissect DT1 messages as RANAP Wireshark
needs to see the connection setup messages (the CR + CC): those are the only
Class-2 messages which contain the SSN which allows Wireshark to know to
dissect the DT1 as RANAP.

So, I don't think there's a problem here.  You should be able to confirm by
capturing the CR+CC that come before the DT1.  If you still have a problem,
feel free to report it here (preferably with a new capture file).  Otherwise,
please close the bug.


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.