can you please help me on the following issue I am having.
Wireshark cannot fully decode NAS field on S1AP protocol. Error (GUI): Unknown-aborting dissection on last few NAS fields
(P.S. WS Windows version decodes NAS fileds just fine!)
Is it a way to attach a small trace file here?
Platform: HP Proliant DL140 running CentOS 6.5
[[email protected] scripts]$ wireshark -v wireshark 1.8.10 (SVN Rev Unknown from unknown)
Copyright 1998-2013 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (32-bit) with GTK+ 2.20.1, with Cairo 1.8.8, with Pango 1.28.1, with GLib 2.26.1, with libpcap, with libz 1.2.3, without POSIX capabilities, with SMI 0.4.8, without c-ares, without ADNS, without Lua, without Python, with GnuTLS 2.8.5, with Gcrypt 1.4.5, with MIT Kerberos, without GeoIP, without PortAudio, with AirPcap.
Running on Linux 2.6.32-431.17.1.el6.i686, with locale en_US.UTF-8, with libpcap version 1.4.0, with libz 1.2.3, GnuTLS 2.8.5, Gcrypt 1.4.5, without AirPcap.
Built using gcc 4.4.7 20120313 (Red Hat 4.4.7-4).
asked 06 Jun '14, 05:06
edited 06 Jun '14, 05:14
It looks like there is a bug affecting Wireshark version 1.8.10. I've tested with your example file on that version as well as 1.8.14 and found the same issue, however when I compile Wireshark 1.10.6 (newest) I do not have that problem.
I suggest compiling 1.10.6 on your Centos server to have the fields decode correctly. I've tested this on Centos 6.4 successfully though I'd be surprised if you have any prerequisite issues on 6.2 (Centos 5 has issues with the GTK prereq but I believe 6.2 would be fine).
answered 06 Jun '14, 13:02
The regression was introduced between 1.8.8 and 1.8.9 versions with svn revision 50675. This was fixed in 1.10 branch in commit 47218 but I missed the fact that the bug has been introduced in the 1.8 branch.
It means that the whole 1.8.X branch cannot decode properly most 3GPP based messages starting from 1.8.9 and up to 1.8.14.
answered 06 Jun '14, 13:20