ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] Decode As... Questions

From: Peter Fuller <randomkodemonkey@xxxxxxxxxxxxxx>
Date: Wed, 30 Apr 2008 19:05:17 +0100

In the past, I have come across some data that was one transport layer carried in another (TCP carrying UDP). My first inclination was to use Wireshark's 'Decode As...' option to force the port in question to continue the dissection using the next transport layer dissector. Is there a reason that the transport layers are not included in the 'Decode As...' list ?

Also, I notice that TPKT is listed twice in verison 1.0

rkm