tcpdump mailing list archives

Re: Request for new DLT value for Wireshark Dissector


From: Schemmel, Hans-Christoph <Hans-Christoph.Schemmel () cinterion com>
Date: Fri, 4 Feb 2011 09:59:45 +0000 (UTC)

Guy Harris <guy <at> alum.mit.edu> writes:


OK, so it's:

      Header_Size: 1 octet

      A sequence of zero or more instances of:

              Msg_ID: 2 octets

              Freq_ID: 2 octets

              Start_Pos: 1 octet

              End_Pos: 1 octet

              Flag: 1 octet

      Direction: 1 octet

      MUX_Frame: the rest of the packet


Yes, that´s correct.

OK, so presumably the parts that don't correspond to a PPP packet would be the
"holes" in the MUX_Frame
field, i.e. the parts that don't correspond to any of the PPP packets
described by Start_Pos and End_Pos. 
How should those parts be interpreted (if at all)?


The parts that don´t correspond to a PPP packet are AT commands or responses
(like "ATI", "AT+CSQ" or "+CSQ: 18,99"). This content is interpreted and
displayed as raw text in the Wireshark subtree for the payload/information of a
packet. These commands and responses don´t need to be dissected.

Kind regards,
Christoph Schemmel

-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: