On Jul 21, 2014, at 11:15 PM, Rayne <hjazz6@xxxxxxxxx> wrote:
> I have some traffic samples where the Layer 2 is PPP and the next protocol field value is 0x0281, which indicates MPLS Unicast. There are 4 bytes following this PPP header before I see the IP header. However, Wireshark has decoded everything after the PPP header as Data.
What version of Wireshark are you using?
> I can't choose the "Decode As" option in this case, as it is greyed out. How can I force Wireshark to decode the 4 bytes after the PPP header as something else, say MPLS in this case?
Use the latest version of Wireshark, which appears to support dissecting packets with a PPP protocol value of 0x0281 as MPLS-over-PPP?