Wireshark mailing list archives

Re: wireshark not deflating ipcomp packets


From: Rupa P V <rupapv () gmail com>
Date: Tue, 23 Apr 2013 13:58:34 -0400

Hi Martin,

Thank you very much. I opened the pcap file in 1.8.6 version of wireshark
in Mac and I could see them decompressed.   Earlier I was using Ubuntu to
view the file and "sudo apt-get install wireshark"  fetches only version
1.2.7.

Rupa.


On Mon, Apr 22, 2013 at 9:15 PM, Martin Visser <martinvisser99 () gmail com>wrote:

There is answer in a thread from a few years ago here -
http://www.wireshark.org/lists/wireshark-bugs/201011/msg00779.html - it
may or may not help.

Also you are using a *very* old version of Wireshark, that often creates a
whole lot of issues.


Regards, Martin

MartinVisser99 () gmail com


On 23 April 2013 02:12, Rupa P V <rupapv () gmail com> wrote:

Hi,

I am trying to ping between two machines with large ICMP packets which
are compressed using DEFLATE. I would prefer to view the decompressed
packets in the expanded packet details, but seems like wireshark is not
decompressing them.  It identifies the packet having IPComp CPI equal to
 DEFLATE , but is not actually deflating the data that follows.

I am using only IPComp, no encryption or authentication in the packet.  I
am using version 1.2.7 of wireshark

Please let me know if anybody knows how to see them decompressed.

-rupapv


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org
?subject=unsubscribe



___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org
?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: