Wireshark-bugs: [Wireshark-bugs] [Bug 9800] Wrong dissection of UDP encapsulated IKEv2 packets a
Date: Sat, 22 Feb 2014 15:27:56 +0000

Comment # 3 on bug 9800 from
I don't think this solution would help. NAT box can change the port to any
value. In the sample I have given it's set to 500 (ISAKMP) due to the nature of
our test.

I have uploaded another sample, in which I've changed the port 500 to 3863
(ASAP) for the first two packets. The port 3863 is still smaller than 4500, and
the dissector for ASAP gets called.

If I understand your solution, it wouldn't work here because the ISAKMP
dissection isn't called at all.


I understand that the problem is rather subtle and not likely to occur
frequently, but we have lost man-hours until we identified the problem as
Wireshark's. I'd like to help other people to avoid the same mistake.


You are receiving this mail because:
  • You are watching all bug changes.