This is our old Q&A Site. Please post any new questions and answers at

I have a custom protocol which combines to make a higher level protocol. It is analogous to HTTP over TCP but it is NOT either of those.

I have implemented a custom dissector for the lower level custom protocol. I used one of the DLT_USER linktypes to register the protocol in my lua plugin. I managed to successfully dissect all of the fields required in this "subprotocol".

Now, I would like to "reassemble" or combine packets of this subprotocol to display the higher level protocol. I am struggling to figure out how to do this. I have found some documentation relating to TCP reassembly, but I am not sure reassembly will work with my custom protocol since it is not TCP and it has its own custom linktype.

I am wondering if a tap is the right solution for me?

asked 30 Jan '17, 08:31

GTOET_half_full's gravatar image

accept rate: 0%

I would recommend visiting the Wireshark Lua/Examples wiki page and reviewing some of the example Lua files provided there. In particular, fpm.lua, which performs reassembly of packets. It's TCP-based, but hopefully it provides a nice starting point for you. I'm not sure, but I don't think the technique employed is limited to only TCP-based protocols.

permanent link

answered 30 Jan '17, 08:50

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

Thank you for your response. I have delved into that file already and it is hard to tell whether or not the techniques in it can work with non-TCP based protocols. I have tried playing with the pinfo.desegment_len but to no avail so far...

(30 Jan '17, 09:15) GTOET_half_full
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 30 Jan '17, 08:31

question was seen: 3,091 times

last updated: 30 Jan '17, 10:36

p​o​w​e​r​e​d by O​S​Q​A