ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 4670] New: Capture containing ESP packets breaks decode of

Date: Wed, 14 Apr 2010 11:16:32 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4670

           Summary: Capture containing ESP packets breaks decode of entire
                    capture
           Product: Wireshark
           Version: 1.3.x (Experimental)
          Platform: x86-64
        OS/Version: Windows 7
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: enfiniti27@xxxxxxxxxxx


Created an attachment (id=4525)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=4525)
Capture that repros the error with ESP/Netmon

Build Information:
Version 1.3.4 (SVN Rev 32340 from /trunk)
--
When opening a capture taken with Netmon 3.3 that contains ESP packets the
entire trace does not decode and displays an error on each frame stating:
Protocol: UNKNOWN Info: WTAP_ENCAP = 0.

If I remove all of the ESP packets from the trace and save it out the trace
opens fine.

I haven't tested this with Netmon versions prior to 3.3 to see if this is
something specific with this version. 

This trace opens fine in Wireshark 1.2.7.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.