Wireshark-bugs: [Wireshark-bugs] [Bug 8229] New: "Decode as..." for entire frames required

Date: Thu, 17 Jan 2013 14:58:56 +0000
Bug ID 8229
Summary "Decode as..." for entire frames required
Classification Unclassified
Product Wireshark
Version 1.8.4
Hardware All
OS All
Status UNCONFIRMED
Severity Major
Priority Low
Component Wireshark
Assignee [email protected]
Reporter [email protected]

Build Information:

--
Some network cards (on Windows Vista: the tunneling adapter) will remove
headers (in my case: the Ethernet header) from the packets when capturing.

As a result Wireshark will decode the first 14 bytes of the IP packet as
Ethernet header and decoding is impossible.

To provide a workaround a "decode entire frame as..." possibility could be
added to Wireshark so the user can select "Ethernet" or "IP".

This would work similar to the "decode as..." feature for certain TCP or UDP
packets that is already available in Wireshark.

Similar to the possibility "decode ALL UDP port 12345 packets as..." feature
there should be the feature "decode ALL frames from this interface as...".

I classified this as bug, not as feature request, because currently decoding of
packets fails without any workaround available.

Thanks

Martin


You are receiving this mail because:
  • You are watching all bug changes.