Noob question here. I wanted to see the performance difference between having all the dissectors turned on vs. only those for the protocols that I was interested in. I ran:
I can see the following protocols used: eth, ip, tcp, udp, icmp, igmp, arp. After adding all of these from the dissectors list I only get dissection up the the ethernet layer, for every packet, everything else it just treats as 'data'. What am I missing?
asked 27 Aug '14, 13:31
Enable all the protocols and then, for a random sample of frames in your capture, look (with wireshark) in the details pane under 'frame' at the generated field 'protocols in frame' to see the list of protocols in the frame.
answered 27 Aug '14, 18:05
Bill Meier ♦♦
edited 27 Aug '14, 18:05