This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I understand that we can use wireshark or tshark to decryptm, in offline mode, IPSec packets that are encrypted using ESP. Is it possible to do the reverse using tshark or another userspace (vs. kernel-space) application? In other words, is there any application that can be used to encrypt IP packets (e.g., captured using wireshark), in offline mode, into IPSec packets using ESP protocol?

Thank you!

asked 12 Feb '16, 08:03

derisavi's gravatar image

derisavi
6112
accept rate: 0%


To answer your question: There might be tools available to do that, but I don't know any. Wireshark can't do that!

What is the purpose of such a tool?

Regards
Kurt

permanent link

answered 13 Feb '16, 04:22

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 13 Feb '16, 04:24

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×34
×20
×19

question asked: 12 Feb '16, 08:03

question was seen: 1,186 times

last updated: 13 Feb '16, 04:24

p​o​w​e​r​e​d by O​S​Q​A