ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] How to decode nested l2tp traffic?

From: Joan <aseques@xxxxxxxxx>
Date: Thu, 22 May 2014 18:31:51 +0200
I am trying to extract the data transmitted into a l2tp tunnel, I am running thsark/tcpdump in the tunnel terminator. What I am using so far is this (4291 is the tunnel number):
  tcpdump -n -i eth3.800 "udp port 1701 && udp[8:2] & 0x80ff == 0x0002 && udp[10:2] == 4291" 


The problem is that I would like to inspect the traffic inside the tunnel, but I could'nt find a reference on this.

Any clues?