This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Bogus IPV6 version (0, must be 6)

0

alt textHi there,

I'm using Wireshark 2.1 for MAC, and I have a problem to decode traces taken in our core network. Every single packet shows the error "Bogus IPV6 version (0, must be 6)", as you can see in the image attached.

It works for my colleagues who are using downgraded versions of Wireshark (v 1.XX).

Is there any way to tweak a preference and make it work in any version?

asked 06 Oct '16, 08:27

artrilla's gravatar image

artrilla
6112
accept rate: 0%

The current stable version is 2.2.1, can you try that version?

(06 Oct '16, 08:29) grahamb ♦

More interesting would be - is the IP version really 0? If you expand the IPv6 layer, what does the value for "Version" say?

(06 Oct '16, 09:11) Jasper ♦♦

Can you share a capture in a publicly accessible spot, e.g. CloudShark?

(07 Oct '16, 04:19) Jaap ♦

HI There,

Same problem is shown in version 2.2.1

If I expand the IP layer, the version shown is 0 (I know, this is incorrect, but previous versions of Wireshark are ignoring this problem)

I just installed v 1.99.8 and the traces are shown without issues.

So the problem is that v2.XX is picky with the validation of values in certain fields.

(07 Oct '16, 11:54) artrilla

Your answer has been converted to a comment as that's how this site works. Please read the FAQ for more information.

(07 Oct '16, 12:40) Jaap ♦

No, the problem is that whatever's capturing your packets is mangling them.

What tool was used to capture that traffic?

(07 Oct '16, 13:59) Guy Harris ♦♦
showing 5 of 6 show 1 more comments