Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Exported PUD proto_name

From: Dario Lombardo <dario.lombardo.ml@xxxxxxxxx>
Date: Mon, 29 Aug 2016 17:45:06 +0200


On Mon, Aug 29, 2016 at 5:30 PM, Pascal Quantin <pascal.quantin@xxxxxxxxx> wrote:
Hi Dario,

2016-08-29 17:03 GMT+02:00 Dario Lombardo <dario.lombardo.ml@xxxxxxxxx>:
I tried again with udpdump using
- http (4 bytes long), aligned ==> works correctly
- dns (3 bytes), not aligned, 1 byte padding ==> works correctly
At this point I guess it's something related to the specific aruba_erm dissector. Alexis, did you try it? Any success?

As explained previously it cannot work as the aruba_erm dissector is not registered by name. So the matching cannot be performed: packet-aruba-erm.c file must be modified with the addition of a register_dissector() call.
Or udpdump must be modified to support also the EXP_PDU_TAG_DISSECTOR_TABLE_NAME case so as to add the udp.port table and the port number.

Ok, thanks, I'll give it a try.