Wireshark-users: Re: [Wireshark-users] Wireshark - TNS Protocol dissector

From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Fri, 21 Apr 2017 16:12:01 -0400


On Fri, Apr 21, 2017 at 3:08 PM, Sridhar N <sridhar.n@xxxxxxxxxxx> wrote:

Dear All

 

It looks that Transparent Network Substrate (TNS), a proprietary Oracle.

Is it not possible to dissect via wireshark?

Any configuration change needs to be done in wireshark GUI?

 

Please guide how to dissect TNS protocol.


Wireshark has a dissector for the TNS protocol.  It appear that it will decode traffic over TCP port 1521 as TNS.  If your traffic is on a different port you can use the Decode-As functionality to tell Wireshark to decode the TCP traffic as TNS.

There were a number of changes made to this dissector since Wireshark 2.2 was released.  If you don't have luck with Wireshark 2.2 you should try one of the 2.3 or automated builds.

There are also some sample captures available on the SampleCaptures page of the wiki:

https://wiki.wireshark.org/SampleCaptures