Re: [Wireshark-users] STOP !!

2007-02-26 Thread Web and Co sprl - Patrick DERWAEL
Yannis, I get the STOP systematically, with no other info. You are right in saying that it does not affect functionality; it is just that I don’t like when it does not what it is supposed to do… BTW: I’m running Wireshark under Win XP Patrick Derwael WEB And Co sprl Rue Hubert

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Frederiek Debruyne
Hi Anders, Did you receive the sample file? Is the Volume-Quota-Threshold AVP recognized in your case? Regards, Frederiek _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Anders Broman (AL/EAB) Sent: vrijdag 23 februari 2007 16:42 To: Community support

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Anders Broman \(AL/EAB\)
Hi, Yes I got the file. I'm quite busy but are hoping to be able to look at it today. Best regards Anders From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frederiek Debruyne Sent: den 26 februari 2007 09:10 To: Community support list for Wireshark

Re: [Wireshark-users] Gr Interface

2007-02-26 Thread Cortes, Joseph
Florent, Are you by any chance capturing ss7 directly using Wireshark? If so what hardware (ss7 card are you using, OS, etc...) Thanks Joe If you have any questions or comments please let me know. Kind Regards Joseph Cortes Current Date Time in Gibraltar Joseph Cortes Wireless

[Wireshark-users] Sniffing across 2 network types

2007-02-26 Thread Antonio cassidy
I have a wireless router that servers all the traffic to my house. Connected to 1 of the Ethernet ports on the router is a linux box. Is it possible to sniff the traffic on the network (wireless clients) using this wired box? Im assuming ARP poisoning is out of the question as the wireless

Re: [Wireshark-users] how to filter a port?

2007-02-26 Thread Ulf Lamping
David Drexler wrote: It's either to or from 'http'. I also tried tcp.port != 80 same results. I want to run the capture realtime and only see the traffic that interests me. Your display filter falls under the A common mistake, try !(tcp.port == 80) instead, which is not the same. HTTP

Re: [Wireshark-users] how to filter a port?

2007-02-26 Thread Guy Harris
David Drexler wrote: It's either to or from 'http'. I also tried tcp.port != 80 same results. I want to run the capture realtime and only see the traffic that interests me. Then you'll need to find out what ports the traffic is going to or coming from - capture filters only work at

Re: [Wireshark-users] Gr Interface

2007-02-26 Thread Anders Broman \(AL/EAB\)
Hi, You can find some information on SS7 capture here http://wiki.wireshark.org/CaptureSetup/SS7 Best regards Anders Från: [EMAIL PROTECTED] genom Cortes, Joseph Skickat: må 2007-02-26 10:52 Till: Community support list for Wireshark Ämne: Re: [Wireshark-users]

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Anders Broman \(AL/EAB\)
Hi, The problem is that Wireshark expects this to be a vendor AVP but it's sent as a normal one. I think this was changed in more recent versions of the 3GPP doc's to be Vendor specific AVP:s. The simplest soulution for you is to edit the XML file and remove Vendor-id=TGPP from the relevant

Re: [Wireshark-users] Jitter wrong in wireshark?

2007-02-26 Thread Lars Ruoff
Hi Anders, since this too is a recurring question, perhaps you (or someone else) could add it to the Wiki, just under what i added last week: http://wiki.wireshark.org/RTP_statistics (bottom). (I'm sorry, i don't have the time right now). br, Lars Anders Broman wrote: Hi, Looking at the

Re: [Wireshark-users] SMB Trans2 FILE_QUERY_INFO Query File Standard Info - what's going on?

2007-02-26 Thread Surlow, Jim
Regarding #2 - I found the following link: http://msdn.microsoft.com/library/default.asp?url=/library/en-us/cifs/pr otocol/smb_com_transaction2_trans2_query_path_information.asp Regarding #1 - Am guessing that the files were written on the unix end and when read from the Windows side it just

Re: [Wireshark-users] how to filter a port?

2007-02-26 Thread Small, James
Thanks Ulf--I didn't realize you could do that, I've been doing not source and not destination - this is much more efficient! --Jim -Original Message- From: [EMAIL PROTECTED] [mailto:wireshark-users- [EMAIL PROTECTED] On Behalf Of Ulf Lamping Sent: Monday, February 26, 2007 5:34 AM

Re: [Wireshark-users] SMB Trans2 FILE_QUERY_INFO Query File Standard Info - what's going on?

2007-02-26 Thread Guy Harris
Surlow, Jim wrote: Regarding #1 – Am guessing that the files were written on the unix end and when read from the Windows side it just keeps searching for a Ctrl-Z EOF rather than Ctrl-D EOF, ...which would be a bit bizarre given that both Windows and UN*X have a the file is this many bytes

Re: [Wireshark-users] Diameter unknown AVPs

2007-02-26 Thread Anders Broman
Hi, Changing the chargecontrol.xml file to: avp name=Volume-Quota-Threshold code=869 mandatory=must may-encrypt=no protected=may type type-name=Unsigned32/ /avp Works for me. Quota-Holding-Time is defined in the dictionary.xml file and in

Re: [Wireshark-users] Jitter wrong in wireshark?

2007-02-26 Thread Anders Broman
Hi, I've added a note on RTP timestamp, please review. Best regards Anders -Ursprungligt meddelande- Från: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] För Lars Ruoff Skickat: den 26 februari 2007 14:46 Till: Community support list for Wireshark Ämne: Re: [Wireshark-users] Jitter wrong in