Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] why cannot I use heur_dissector_add("ip", .....

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Sun, 26 Jun 2011 14:17:37 -0700
On Jun 26, 2011, at 2:09 PM, John x wrote:

> these packets run directly atop IP, any suggestions?

	1) Get a protocol number from the IANA and use it, instead of some hack based on the TTL value.

	2) Hack the IP dissector in a private version of Wireshark.