ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 6316] Huawei GRE ERSPAN is not decoded properly

Date: Fri, 28 Oct 2011 11:27:16 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6316

--- Comment #4 from Sergey V. Lobanov <sergey@xxxxxxxxxx> 2011-10-28 11:27:16 PDT ---
(In reply to comment #2)
> See Bug #6504, there is the some issue (i propose a patch to fix this)

Thanks for your patch. After applying your
patch(https://bugs.wireshark.org/bugzilla/attachment.cgi?id=7328 ), it was
possible to decode my dump(erspan-huawei-source.pcap), but it will not work if
the mac address from mirrored L2 frame starts with 00010000b. It conflicts with
version 1 of cisco erspan. I have attached an
example(erspan-huawei-source-2.pcap)

I think that in the settings of the erpsan protocol should be an option to
FORCE decode erspan frames as fake(not cisco) erspan frame.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.