This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

The Cisco Nexus 3548 has ability to add a ptp clocked time tag to each ingress packet on egress. Has anyone build a dissector to parse this?
bytes 13/14 Ethertype 0xBB85
bytes 15-20 6 byte time tick in NS
bytes 21/22 actual ethertype (0x0800 for IP or 8100 for dotQ tag).

Steve

asked 13 Jun '16, 08:29

steve_merc's gravatar image

steve_merc
6446
accept rate: 0%

edited 13 Jun '16, 08:31

sindy's gravatar image

sindy
6.0k4851


Please raise an enhancement request on bugzilla with a sample trace file.

permanent link

answered 13 Jun '16, 10:11

Anders's gravatar image

Anders ♦
4.6k952
accept rate: 17%

Thank you for info. I will do.

Steve

Bug 12518

(13 Jun '16, 11:23) steve_merc

(I converted Ander's comment to an answer since it answers the question: no, Wireshark doesn't support this today.)

(13 Jun '16, 12:18) JeffMorriss ♦

And if you cannot wait, you may use Lua to cover the time until someone picks up your enhancement request. From the description the dissection of the header doesn't seem to be a complex task.

(14 Jun '16, 00:55) sindy
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×637
×43
×5

question asked: 13 Jun '16, 08:29

question was seen: 802 times

last updated: 14 Jun '16, 02:20

p​o​w​e​r​e​d by O​S​Q​A