Wireshark gives me a "malformed packet" message every time my DNP 3 responses are larger that a single frame. I am analyzing DNP over serial. I am trying to determine the setting that will allow decoding of greater that 255 byte packets, but am not having any luck. Any ideas? asked 28 Jun '17, 15:59 Kurt |
One Answer:
Go answered 07 Jul '17, 00:11 sindy I haven't used this service before. I posted a capture on Cloudshark as requested (11 Jul '17, 12:50) Kurt Can you provide a link to it? (11 Jul '17, 12:51) sindy |
Can you share a capture in a publicly accessible spot, e.g. CloudShark, Google Drive, DropBox etc?
That's not really necessary. I simply need to know how to set Wireshark to decide more than one frame of serial data. I figured it out with ASE2000, I just need help with Wireshark.
As the DNP3 dissector successfully reassembles DNP3 traffic over both TCP and UDP, I suspect that the fact that your capture is "serial" may be the issue, hence the need to see the capture.
How exactly did you make the capture file?