This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

i am seeing ENTTEC HEAD unknown so what basically ENTTEC IS :----alt text

BELOW I S THE IMAGE

asked 26 Nov '14, 23:39

Manish%20Rajput's gravatar image

Manish Rajput
1111
accept rate: 0%


It's an indication that the dissector for ENTTEC's DMX on Ethernet protocol needs to be fixed so that TCP packets that happen to use the same port number as that protocol, but that don't appear to be DMX-on-Ethernet packets, don't get dissected as DMX-on-Ethernet packets.

Unlike, for example, Ethernet type values, TCP and UDP ports are not guaranteed to be reliable indications of the protocol being used, so there's always the chance that Wireshark will misidentify protocols running on top of TCP or UDP. There are ways in which "false positives", such as identifying traffic to or from port 3333 as DMX-on-Ethernet packets, can be reduced.

Please file a bug on this at the Wireshark Bugzilla, so we can keep track of it.

permanent link

answered 27 Nov '14, 11:51

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×87
×6

question asked: 26 Nov '14, 23:39

question was seen: 4,623 times

last updated: 27 Nov '14, 11:51

p​o​w​e​r​e​d by O​S​Q​A