Wireshark-users: Re: [Wireshark-users] wireshark not deflating ipcomp packets
From: Martin Visser <martinvisser99@xxxxxxxxx>
Date: Tue, 23 Apr 2013 11:15:15 +1000
There is answer in a thread from a few years ago here - http://www.wireshark.org/lists/wireshark-bugs/201011/msg00779.html - it may or may not help.

Also you are using a *very* old version of Wireshark, that often creates a whole lot of issues.




On 23 April 2013 02:12, Rupa P V <rupapv@xxxxxxxxx> wrote:
Hi,

I am trying to ping between two machines with large ICMP packets which are compressed using DEFLATE. I would prefer to view the decompressed packets in the expanded packet details, but seems like wireshark is not decompressing them.  It identifies the packet having IPComp CPI equal to  DEFLATE , but is not actually deflating the data that follows.  

I am using only IPComp, no encryption or authentication in the packet.  I am using version 1.2.7 of wireshark

Please let me know if anybody knows how to see them decompressed.

-rupapv

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe