Wireshark-dev: [Wireshark-dev] The fate of TRB-Protocol (looking for ways to embed metadata)

From: "Nick Zavaritsky" <nick.zavaritsky@xxxxxxxxxx>
Date: Mon, 16 May 2022 05:43:37 +0000
Dear Wireshark hackers,

I’m looking for ways to embed custom metadata in a pcapng file. Ideally, it should be possible to examine the metadata in sufficiently recent Wireshark without installing custom extensions.

Context: EMnify offers a cloud connectivity platform for IoT devices. A client can request a packet capture for troubleshooting purposes. The capture is delivered as a pcapng file. We’d like to include additional metadata, e.g. the reason a packet is being dropped; e.g. external port and IP address the packet will assume after traversing NAT.

TRB Protocol [1] looks promising. Unfortunately, it looks like is has never shipped. Could anyone shed some light on its fate? Any chance it will ship this year?

Finally, if there are other ways to embed and display custom metadata in Wireshark besides TRB Protocol, I will appreciate the pointer.

Best,

N

[1] https://wiki.wireshark.org/TRB-Protocol