In the past, I have come across some data that was one transport layer carried in another (TCP carrying UDP). My first inclination was to use Wireshark's 'Decode As...' option to force the port in question to continue the dissection using the next transport layer dissector. Is there a reason that the transport layers are not included in the 'Decode As...' list ?
Also, I notice that TPKT is listed twice in verison 1.0 rkm _______________________________________________ Wireshark-dev mailing list Wireshark-dev@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-dev