I encountered a problem when analyzing a SCTP packet capture file. There are 2 Diameter messages in one SCTP chunk, but wireshark can only parse and display the first one. I can locate the second message in the bottom binary window but can't see it in the middle packet detail window.
I found some specification say there couldn't be more than 1 message in one chunk. But I found there actually has 2 diameter messages in one chunk. Chunk size is the size of the two messages. Is it an assembling errors or the implementation just like it?
Anyone encountered similar issue before? Thanks for your discussion and sharing.
asked 11 Feb '14, 22:42
Well I've never seen that before but anyway I know Wireshark won't handle it. Wireshark expects only one Diameter message per SCTP chunk. (Having one message or PDU per chunk is half the point of SCTP--no more of that "this is just a byte stream" mess you have with TCP.)
answered 12 Feb '14, 05:58