This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

what is ENTTEC IN A PCAP FILE

0

i am seeing ENTTEC HEAD unknown so what basically ENTTEC IS :----alt text

BELOW I S THE IMAGE

asked 26 Nov '14, 23:39

Manish%20Rajput's gravatar image

Manish Rajput
1111
accept rate: 0%


One Answer:

1

It's an indication that the dissector for ENTTEC's DMX on Ethernet protocol needs to be fixed so that TCP packets that happen to use the same port number as that protocol, but that don't appear to be DMX-on-Ethernet packets, don't get dissected as DMX-on-Ethernet packets.

Unlike, for example, Ethernet type values, TCP and UDP ports are not guaranteed to be reliable indications of the protocol being used, so there's always the chance that Wireshark will misidentify protocols running on top of TCP or UDP. There are ways in which "false positives", such as identifying traffic to or from port 3333 as DMX-on-Ethernet packets, can be reduced.

Please file a bug on this at the Wireshark Bugzilla, so we can keep track of it.

answered 27 Nov '14, 11:51

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%