Wireshark-users: Re: [Wireshark-users] ISDN Layer 3 decode

From: "Keith French" <keithfrench@xxxxxxxxxxxxx>
Date: Fri, 21 Oct 2011 22:27:26 +0100
It does have an Export option to Ethereal, but all packets show up as malformed. It can be saved in its own format (which I would think is highly protected) being a commercial product, or in CSV or Text. The other analyser I mentioned that uses Wireshark saves its D channel decodes in TRC format.

-----Original Message----- From: Stephen Fisher
Sent: Friday, October 21, 2011 7:28 PM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] ISDN Layer 3 decode

On Fri, Oct 21, 2011 at 07:21:33PM +0100, Keith French wrote:

I have an ISDN (E1) analyser that cannot decode Q.Sig’s ASN1 notation
holding information about call transfers etc. I know from another
analyser that can export its D channel decode in Wireshark format,
that Wireshark has an excellent decode for this.

Can it save in a pcap or other data file format?  Wireshark supports
many file formats, and it's relatively easy to add new ones to wiretap
if the format is well documented.

Is there any way I can take the raw hex at layers 2 & 3 (LAPD layer 2)
for each message and via something like text2pcap get Wireshark to
decode this for me?

Is it in the right format?  According to the text2pcap man page (also
available online at
http://www.wireshark.org/docs/man-pages/text2pcap.html), it needs the
offset and then the hex.  There may be options to change this
requirement though.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe