I am trying to import below ICMP6 destination unreachable packet in hex dump into Wireshark but it keeps stripping last byte (34) here and then indicate checksum is invalid. I tried remove '34' and re-import again, in that case '4e' would be stripped instead...
This is a Raw IPv6 packet and I imported it with below setting: Offsets: hexadecimal Encapsulation type: Raw IPv6
I tried import an ICMPv4 destination unreachable packet and it worked fine.
I am wondering if I am missing something here ? Any idea is well appreciated! thanks!
0000 60 00 00 00 00 24 3a 7c 00 00 00 00 00 00 00 00
asked 15 Jan '15, 15:02
edited 15 Jan '15, 15:04
This function is derived from text2pcap, and
Text2pcap understands a hexdump of the form generated by od -Ax -tx1 -v. In other words, each byte is individually displayed and surrounded with a space.
It that 'surrounded with a space' that's tripping you up. Add a trailing space and you should be fine.
answered 16 Jan '15, 07:12