Wireshark-dev: Re: [Wireshark-dev] Query regrading RRC decoder
From: "Anders Broman (AL/EAB)" <[email protected]>
Date: Thu, 16 Aug 2007 13:40:32 +0200
The RRC dissector is kind of standalone now and only called for some RRC
messages tunneled in GSM MAP
(I think it was) but can be called by name from any other dissector.

I don't have any deeper knowledge of the GSM/UMTS protocol stack on the
Iu(?) interfaces.
>From your previous posts I guess that you want to decode those messages
sent over UDP
Are those messages generated by a trace tool or some Nokia proprietary
solution or specified by
3GPP in some spec (which?).

Again from previous post it sounded like those messages are

Wireshark can't decode these messages without code changes.

If you would want to atempt those code changes  from Martin's post I
infer that the
FP part could be dissected by the UMTS FP dissector(I forgot the name of
the file) providing
Some additional information was given to the dissector by preferences or
a intermediate
Dissector for the UDP trace or transport format used by your

I don't think we have a MAC (3GPP spec ref?) dissector so one have to be
Some one mentioned that this layer may be Encrypted. Is that the case
for your trace?
If so you might have to add decryption to get to RRC.

It would be easier to anser your questions given some more background.

-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of
[email protected]
Sent: den 16 augusti 2007 11:52
To: Developer support list for Wireshark
Subject: [Wireshark-dev] Query regrading RRC decoder


wireshark 0.99.6 have a RRC decoder but I want to know RRC decoder how
to work.
Means, RRC seating over which protocol.
If I wants to RRC over FP it is possible or not.

Thanks & Regards,

***********************  Aricent-Unclassified   ***********************

"DISCLAIMER: This message is proprietary to Aricent  and is intended
solely for the use of the individual to whom it is addressed. It may
contain privileged or confidential information and should not be
circulated or used for any purpose other than for what it is intended.
If you have received this message in error, please notify the originator
immediately. If you are not the intended recipient, you are notified
that you are strictly prohibited from using, copying, altering, or
disclosing the contents of this message. Aricent accepts no
responsibility for loss or damage arising from the use of the
information transmitted by this email including damage from virus."

Wireshark-dev mailing list
[email protected]