Re: [Wireshark-users] How to decode AVP 1003 and 1022 ??

2007-08-28 Thread Anders Broman (AL/EAB)
Hi, Can you give a reference to a 3GPP dockument defining Access-Network-Charging-Identifier-Ty I can't find it. Regards Anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Leonard Wu (liwu) Sent: den 28 augusti 2007 07:22 To: Community support list

Re: [Wireshark-users] Is there case and strong evidence thatwireshark/ethereal is accepted and used by any big operatorslike vodafone, TIM?

2007-05-03 Thread Anders Broman \(AL/EAB\)
Yes :-) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of billyjeans Sent: den 3 maj 2007 08:31 To: wireshark-users@wireshark.org Subject: [Wireshark-users] Is there case and strong evidence thatwireshark/ethereal is accepted and used by any big

Re: [Wireshark-users] Is it possible to decode the CDMA IOS5 layer overSUA?

2007-04-27 Thread Anders Broman \(AL/EAB\)
Hi, This may be a problem with the way Wireshak sets up associations for SCCP connections the same funktionallity is not made for SUA I think can you share a small sample file showing the problem? Regards Anders Från: [EMAIL PROTECTED] genom Yang Zhe Skickat:

Re: [Wireshark-users] Is it possible to decode the CDMA IOS5 layerover SUA?

2007-04-27 Thread Anders Broman \(AL/EAB\)
Hi, I haven't looked but should more code be shared between the SUA and SCCP dissector in order to not implement the same stuff twice? Regards Anders Från: [EMAIL PROTECTED] genom Luis Ontanon Skickat: fr 2007-04-27 16:24 Till: Community support list for

Re: [Wireshark-users] Assembling of fragmented IP protocol packets

2007-04-24 Thread Anders Broman \(AL/EAB\)
Hi, How about Edit-preferences-Protocols-IP Reassemble Fragmented IP datagrams = True ? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Franz Edler Sent: den 24 april 2007 18:47 To: wireshark-users@wireshark.org Subject: [Wireshark-users] Assembling of

Re: [Wireshark-users] Decoding MMS/COTP/TPKT/TCP

2007-04-23 Thread Anders Broman \(AL/EAB\)
Hi, The problem here is that you must capture the setup part where the tie to MMS OID is made. Best regards Anders From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kunjarteer Sent: den 17 april 2007 00:16 To: wireshark-users@wireshark.org Subject:

Re: [Wireshark-users] VoIP Analysis for Dummies

2007-03-22 Thread Anders Broman \(AL/EAB\)
Hi, Are the packets from the Phone to the Asterix sever UDP or TCP packets if you examine a few of those packets Can you see SIP inside?(look in the bytes pane as it's a text base protocol you should be able to identify it) If they are TCP packets what ports are used? (Check

Re: [Wireshark-users] TCP capture problem,

2007-03-15 Thread Anders Broman \(AL/EAB\)
Hi, What version of Wireshark and WinPcap are you using? Wiresark 0.99.5 and WinPcap 4.0 are the latest versions. Best regards Anders From: [EMAIL PROTECTED] on behalf of Jarkko Nevala Sent: Thu 3/15/2007 1:23 PM To: wireshark-users@wireshark.org Subject:

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Anders Broman \(AL/EAB\)
, Frederiek From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Anders Broman (AL/EAB) Sent: vrijdag 23 februari 2007 16:04 To: Community support list for Wireshark Subject: SV: [Wireshark-users] Diameter unknown AVPs Hi, AVP:s can be dissected either

Re: [Wireshark-users] Gr Interface

2007-02-26 Thread Anders Broman \(AL/EAB\)
Hi, You can find some information on SS7 capture here http://wiki.wireshark.org/CaptureSetup/SS7 Best regards Anders Från: [EMAIL PROTECTED] genom Cortes, Joseph Skickat: må 2007-02-26 10:52 Till: Community support list for Wireshark Ämne: Re: [Wireshark-users]

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Anders Broman \(AL/EAB\)
receive the sample file? Is the Volume-Quota-Threshold AVP recognized in your case? Regards, Frederiek From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Anders Broman (AL/EAB) Sent: vrijdag 23 februari 2007 16:42 To: Community support list

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-23 Thread Anders Broman \(AL/EAB\)
Hi, AVP:s can be dissected either by the data in the file packet-diameter-defs.h or by the Diameter XML files if those preferences are set. See the wiki page for details. The XML library is more updated than the file. What AVP:s are not recognised? Best regards Anders

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-23 Thread Anders Broman \(AL/EAB\)
/ /avp I'm not sure whether this should be sufficient. It does not seem to be, since the AVP is still not recognized. Regards, Frederiek From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Anders Broman (AL/EAB) Sent: vrijdag 23 februari 2007

Re: [Wireshark-users] Jitter wrong in wireshark?

2007-02-23 Thread Anders Broman \(AL/EAB\)
Hi, Which codec is used? Best regards Anders Från: [EMAIL PROTECTED] genom [EMAIL PROTECTED] Skickat: fr 2007-02-23 16:53 Till: wireshark-users@wireshark.org Ämne: [Wireshark-users] Jitter wrong in wireshark? Hi All, Below is a rtp analysis from a wireshark

Re: [Wireshark-users] Question on Ethereal

2007-02-16 Thread Anders Broman \(AL/EAB\)
Hi, Note that Malformed packet can have at least two reasons: - The packet is malformed - The dissector of the protocol has a bug If you save the ´Malformed packet to file and try to open it in the latest version of Wireshark 0.99.5 does it show up as malformed then? ( Bugs in the dissector

Re: [Wireshark-users] Convert G.729 to audio?

2007-01-05 Thread Anders Broman \(AL/EAB\)
Hi, See http://wiki.wireshark.org/RTP_statistics BR Anders From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Chet Seligman Sent: den 5 januari 2007 16:27 To: wireshark-users@wireshark.org Subject: [Wireshark-users] Convert G.729 to audio? Is there

Re: [Wireshark-users] How tshark identify SMS-DELIVERY or SMS-DELIVERY-REPORT

2006-12-18 Thread Anders Broman \(AL/EAB\)
Hi, In gsm_map pinfo-p2p_dir = P2P_DIR_RECV; is set of there is an ISDN address string in there and if SeriveCentreAddress is present pinfo-p2p_dir = P2P_DIR_SENT; is set. The filter is gsm_map BR Anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of

Re: [Wireshark-users] Problems with dumpcap and ringbuffer

2006-11-24 Thread Anders Broman \(AL/EAB\)
Hi, What version is that? I think there was a ringbuffer problem solved a while back... BR Anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Lars Ruoff Sent: den 24 november 2006 13:19 To: Wireshark-users Subject: [Wireshark-users] Problems with

Re: [Wireshark-users] multiple giop in one packet display last request_op in Info field...any way to change this?

2006-11-03 Thread Anders Broman \(AL/EAB\)
Hi, No, the only thing that can be done is to display all the requests in the packet not only the last one by using col_set_fence to stop the dissector from overwriting stuff allready put in the info field. BR Anders From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ivan

Re: [Wireshark-users] Problem Opening 8M capture in Wireshark V0.99.4

2006-11-01 Thread Anders Broman \(AL/EAB\)
Hi, This is not anproblem per se you can just ack the pop ups. The reason for the messages are that some frames are recognised as Diameter frames and you haven't got the libxml2.dll in your Wireshark direcory. See the wiki page on Diameter. Check also the preferences for Diameter and

Re: [Wireshark-users] H.323 call flow

2006-10-10 Thread Anders Broman \(AL/EAB\)
Hi, A tool can be found at http://sipp.sourceforge.net/ Some other links: http://wiki.wireshark.org/VoIP_calls And http://wiki.wireshark.org/SIP?action=showredirect=Protocols%2Fsip BR Anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Chris Swinney

Re: [Wireshark-users] VoIP analysis and assessment

2006-10-06 Thread Anders Broman \(AL/EAB\)
Hi, You might want to use the new RTPplay function in Wireshark you'll have to download a development version to try it out. BR Anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frank Bulk Sent: den 6 oktober 2006 06:40 To: 'Community support list

Re: [Wireshark-users] IEC 60870-5-104 Plugin?

2006-09-22 Thread Anders Broman \(AL/EAB\)
Hi, There is a recent entry at: http://www.ethereal.com/lists/ethereal-dev/200609/msg5.html Brg Anders -Original Message- From: [EMAIL PROTECTED] on behalf of Ulf Lamping Sent: Fri 9/22/2006 9:49 AM To: Community support list for Wireshark Subject: Re: [Wireshark-users] IEC

Re: [Wireshark-users] diameter over udp

2006-07-05 Thread Anders Broman \(AL/EAB\)
Hi, I don't know if any thing has been removed, but given a small trace it should be easy to add UDP decoding to the current dissector. Brg Anders -Original Message- From: [EMAIL PROTECTED] on behalf of Eric Hester Sent: Wed 7/5/2006 4:52 PM To: wireshark-users@wireshark.org Subject: