Wireshark-dev: Re: [Wireshark-dev] h.223 dissector: maybe a bug, mabe a fix?
From: Richard van der Hoff <richardv@xxxxxxxxxxxxx>
Date: Fri, 19 Jan 2007 12:33:18 +0000
Anders Broman wrote:
Hi,
It would be more interesting and useful to add the capability in
wiretap to read the raw h.223 data with a pcap header. Others can perhaps
help with hints on how to do that.

The H.223 dissector expects its parent protocol to support defragmentation; if you just give wireshark the raw data, I don't think you'll get the defragmentation, as it's quite specific to individual protocols such as TCP. Fabio's approach makes sense to me.

Fabio, I'm away next week, but I'll have a look at your patch when I get back.

Regards,

Richard


--
Richard van der Hoff <richardv@xxxxxxxxxxxxx>
Systems Analyst
Tel: +44 (0) 845 666 7778
http://www.mxtelecom.com