Wireshark mailing list archives

Re: why cannot I use heur_dissector_add("ip", .....


From: John x <xiachangqin66 () hotmail com>
Date: Mon, 27 Jun 2011 05:09:26 +0800


these packets run directly atop IP, any suggestions?

Thanks

From: guy () alum mit edu
Date: Sun, 26 Jun 2011 13:48:07 -0700
To: wireshark-dev () wireshark org
Subject: Re: [Wireshark-dev] why cannot I use heur_dissector_add("ip", .....


On Jun 26, 2011, at 1:44 PM, John x wrote:

Yes it is that TTL changes in-flight. But my packets are captured on a specific link, there are only 2 or 3 kinds 
of packets. The way to distinguish them is only the TTL value.

So these packets run *directly* atop IP?

Or do they run atop UDP or TCP or some other protocol?
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
                                          
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: