This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.
0
1

Dears,

I have a setup in the lab where I have configured ERSPAN on Cisco ACI Fabric which pretty similar to ERSPAN on Nexus switches 7k or 5K , I got the capture where I can see only the outer header for the packets but it's not helpful.

So I want to decapsulate/decode the ERSPAN packets where I can see the inner header for the captured pkts. I am using Wireshark 1.12.7 on windows 2008 server. it worth mentioning too that both source and destination are VMs.

I have attached a snapshot for the captured packets from wireshark.

How is this can be achieved ? I am looking for a decoder integrated with wireshark ?

Regards Mohammed ElSherbinyalt text

asked 11 Oct '15, 02:58

mohammedelsherbiny's gravatar image

mohammedelsh...
6122
accept rate: 0%

Did you try setting the Erspan preference "FORCE to decode fake ERSPAN frame" to TRUE (as suggested in the expert message and which may or may not be helpful) ?

If setting the preference doesn't work, examining the capture will probably be the best way for us to help you.

Can you provide the capture ? (Upload it to something like dropbox) and provide a link here.

(11 Oct '15, 04:35) Bill Meier ♦♦

I have the same problem although it was solved in the client by applying the "Force to decode fake ERSPAN" option. Does anyone know if/how this is possible using TSHARK?

(30 Dec '16, 03:57) xoomg

Yes, you can add -o erspan.fake_erspan:TRUE to your tshark command.

(30 Dec '16, 07:43) SYN-bit ♦♦

choose „Preferences > Protocols > ERSPAN“ select “Force to decode fake ERSPAN frame”

permanent link

answered 19 Jun '17, 03:33

briantilburgs's gravatar image

briantilburgs
61
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×43
×23
×9
×8

question asked: 11 Oct '15, 02:58

question was seen: 5,637 times

last updated: 19 Jun '17, 03:33

p​o​w​e​r​e​d by O​S​Q​A