This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Dear Team, I am trying read diameter pcap dump with tshark by filtering with "session ID" and redirected the output to /tmp folder, when i convert this file (HEX or ASCII) to pcap in text2pcap, it is showing wrong protocols..

tshark -x -r InputFile.pcap -V "diameter.Session-Id == \"MMEC78.MMEGI8024\" > /tmp/filter (-x used for saving in HEX)

text2pcap filter outut.pcap --->here my file is converted but it opens in Ethernet/TDMoP/anyother protocols, instead of Diameter..I found this problem with diameter trace file only as this method works fine for my other protocol trace file example.GSM_MAP trace..

alt text

please help...

asked 21 Feb, 06:43

sudheer628's gravatar image

sudheer628
6224
accept rate: 0%


Answer: Got the solution by friend, that my tshark is reading pcap in HEX & non HEX data format, text2pcap is unable to recognize non HEX data..issue resolved by using proper encapsulation type. we used below command which simply consider HEX format only

text2pcap -l 113 input output.pcap (where 113 represents the encapsulation of Linux trace)

permanent link

answered 24 Feb, 10:43

sudheer628's gravatar image

sudheer628
6224
accept rate: 0%

edited 13 Mar, 00:05

Hi, did you attempt for IPv4 or IPv6 ? If IPv6 could you please help with some more details ? thanks in advance

(13 Mar, 09:29) Vijay Gharge

As the text2pcap man page indicates, you can use the -a option:

Enables ASCII text dump identification. It allows to identify the start of the ASCII text dump and not include it in the packet even if it looks like HEX.

permanent link

answered 13 Mar, 07:40

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×58
×19

question asked: 21 Feb, 06:43

question was seen: 717 times

last updated: 13 Mar, 09:29

p​o​w​e​r​e​d by O​S​Q​A