Hi,
We have some interns that have written a dissector for CAN and is also have the possibility do dissect protocols running on CAN. To capture the CAN packets special hardware is required, for now they have a simple app that reads the CAN
packets and encapsulates them into an Ethernet frame and passes it on to a NIC.
Today the CAN data is encapsulated as a in the 802.3 frames using the SNAP header on an unregistered oui. This is a similar to how BACnet MS/TP frames are captured on RS-485 and passes them on to Wireshark.
Is this CAN dissector that you could consider adding to Wireshark? If yes what would be the preferable way to encapsulate the CAN frames to have them passed on to Wireshark?
Thanks,
Joakim