This is our old Q&A Site. Please post any new questions and answers at

LLTD is the Link Layer Topology Discovery introduced by Microsoft with Windows Vista.

As of now Wireshark recognizes LLTD frames by Ethertype but does not decode the content.

Wiki provides a link to a dissector. What are the chances of getting the LLTD dissector into the standard Wireshark build?

asked 18 Apr '11, 02:24

packethunter's gravatar image

accept rate: 8%

Presumably, the MS-LLTD wiki page is the one you're referring to. The link from that page to the dissector indicates that it was developed against 1.0.4, so in all likelihood some changes would be needed before it could be incorporated. So I'd say the first step would be for someone to update the dissector to build against the trunk. After that, an enhancement bug request should be filed at with the updated dissector attached.

permanent link

answered 18 Apr '11, 07:45

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

I just realized that Wireshark is doing a great job on decoding LLTD.

Closing the question is overdue.

Thank you to all developers for keeping Wireshark great :)

(17 Feb '17, 12:13) packethunter
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 18 Apr '11, 02:24

question was seen: 4,426 times

last updated: 17 Feb '17, 12:13

p​o​w​e​r​e​d by O​S​Q​A