In the low part of Wireshark I see : SNCFRA ME , please advise ? is it relate to the fact that I am using sap snc (secure network connection)? asked 22 Feb '17, 00:16 hadarba63 edited 22 Feb '17, 04:38 grahamb ♦ |
2 Answers:
Yes....... answered 22 Feb '17, 05:30 Jaap ♦ |
Hello! Yes, that is the "eyecatcher" for the use of SNC. You can use the following plugin to see some SAPGUI/Diag protocol data (e.g. field "sapdiag.header.compress" for if the Diag packet is only compressed or SNC is enabled) along with the SNC Frame container: https://github.com/CoreSecurity/SAP-Dissection-plug-in-for-Wireshark I'm planning to add support for more detailed dissection of SNC packets around late March (after publishing https://www.troopers.de/events/troopers17/763_intercepting_sap_snc-protected_traffic/). answered 23 Feb '17, 12:17 mgallo |