Wireshark-users: Re: [Wireshark-users] h.248 over SCTP
From: "Anders Broman" <a.broman@xxxxxxxxx>
Date: Sat, 12 Jan 2008 23:41:14 +0100
Hi,
It does on my traces but if H248 is not detected in yours the filter won't
work. At a glance at the code SCTP port does not work for H.248(not
implermented(yet)) ppid *should* work.
Regards
Anders

-----Ursprungligt meddelande-----
Från: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] För Ariel Burbaickij
Skickat: den 12 januari 2008 17:02
Till: wireshark-users@xxxxxxxxxxxxx
Ämne: Re: [Wireshark-users] h.248 over SCTP

Hello Anders,
glad to see your again,
I will provide detailed answers on Monday, 14.01.2007 as I am
away from equipment. However,  if I understand the nature of your
questions correctly -- they imply that there are some limitations.
Is it correct? How about the fact that filter h248 does not work
in case of tranfer over SCTP?

/wbr
Ariel Burbaickij
On Jan 12, 2008 12:50 PM, Anders Broman <a.broman@xxxxxxxxx> wrote:
> Hi,
> Traces I have of H.248 over SCTP decodes...
> Is PPID 7 used? Is it Binary or text?
> Can you send a small sample trace?
> Regards
> Anders
>
> -----Ursprungligt meddelande-----
> Från: wireshark-users-bounces@xxxxxxxxxxxxx
> [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] För Ariel Burbaickij
> Skickat: den 12 januari 2008 11:02
> Till: wireshark-users@xxxxxxxxxxxxx
> Ämne: [Wireshark-users] h.248 over SCTP
>
>
> Hello all,
> we use h.248 over SCTP and wireshark behaves in such a way that I at least
> need your advise as of now I still hesistate to submit bug report.
> We observe following:
> 1) It is not possible to filter on h248 or MEGACO filters user needs
> to enter sctp protocol payload
>     number in order to get the packets of interest.
> 2) h.248 content is not being decoded properly, also after applying
> "decode as..." functionality
>
> 3) it is not possible to select H.248/MEGACO if decode should be based
> on port and not on PPID
>
> Question: Is all this known bugs/behaviour, do I do something wrong
> while working with it or should I submit
> bug report?
>
>
> /wbr
> Ariel Burbaickij
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> http://www.wireshark.org/mailman/listinfo/wireshark-users
>
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users