Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 12568] Wireshark is marking BGP FlowSpec NLRI as malformed

Date: Wed, 29 Jun 2016 14:20:16 +0000

Comment # 8 on bug 12568 from
Hi Guys,

I was the one writing this piece of code.

I don't believe the patch is valid and I need to check if mine is working fine
(normally it should... but like said at the end of "someone like it hot" movie,
nobody's perfect !)

One thing which is 100% sure is that the proposed patch doesn't comply with
RFC5575. As an example, with the patch proposed what will happen if NLRI is
above 255 bytes ... 

Please note that certain routers also suffer from BUG's on this field ... As an
example, JunOS was not encoding the value properly ...

Would it be possible to load a little bit more the NLRI such that we go above
255 bytes and see how the field is coded by the router ?

Does it makes sense ?

Thanks Matt.


You are receiving this mail because:
  • You are watching all bug changes.