Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Decode as different protocol

From: Manolis Katsidoniotis <manoska@xxxxxxxxx>
Date: Tue, 24 Jan 2012 17:33:06 +0200
Hello all

In the attached snapshot, frame 2767 is a sip packet sent via TCP to destination port 5500.
I'm assuming that because of the port number, wireshark assumes that it is a vnc frame (Virtual Network Computing).

I change this by selecting the packet and using the "Decode As" option.
However this needs to be done every time I open wireshark.
Does anyone happen to be aware of doing this permanent (i.e. modifying some start-up file)?

Thanks in advance
Manolis

Attachment: capture_snapshot.jpg
Description: JPEG image