Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] lwapp decode

From: "mail.ag" <mail.ag@xxxxxxxxxxxxxxxxxxx>
Date: Fri, 03 Nov 2006 15:46:55 -0500
Greetings:

I'm having trouble decoding an LWAPP encapsulated packet.  Attached is a
capture file with two packets.  It was taken on the *wired* side of the
access point, not the RF side.

The two packets are an ICMP echo request and reply. 

Wireshark (Version 0.99.4 (SVN Rev 19757)) is calling the packet
malformed and decoding the ICMP payload (ACBDEFG....) has 802.11
Wireless LAN Management Frame Reserved Tags.

The 'Frame' Section of the decode indicates that the protocols in the
frame are eth:ip:udp:lwapp:wlan, but given that it is ICMP encapsulated
in LWAPP, should the list be eth:ip:udp:lwapp:icmp?

I tried forcing the decode as LWAPP-L3 which did not help.

This is a Circo Airespace 4.0.x setup.

Can Wireshark decode these types of LWAPP frames?

Thank you.

Attachment: lwapp-icmp.pcap
Description: Binary data