Re: [Wireshark-users] MPLS over UDP decoding

2018-12-28 Thread Guy Harris
On Dec 28, 2018, at 2:36 PM, Yang Yu wrote: > On Fri, Dec 28, 2018 at 1:07 PM Guy Harris wrote: >> From looking at the code, the logic appears to be "is the traffic to or from >> UDP port 6635?" >> >> So *is* the traffic to or from UDP port 6635? > > indeed udp.dstport is 6635 (IANA assigned

Re: [Wireshark-users] MPLS over UDP decoding

2018-12-28 Thread Yang Yu
On Fri, Dec 28, 2018 at 1:07 PM Guy Harris wrote: > From looking at the code, the logic appears to be "is the traffic to or from > UDP port 6635?" > > So *is* the traffic to or from UDP port 6635? indeed udp.dstport is 6635 (IANA assigned for mpls-udp), so it turned out a host was using

Re: [Wireshark-users] MPLS over UDP decoding

2018-12-28 Thread Guy Harris
On Dec 27, 2018, at 3:01 PM, Yang Yu wrote: > In a packet capture of sFlow export packets, I noticed some sFlow > samples were decoded as MPLS over UDP. The sFlow sampled packet was > actually just a UDP VoIP packet with no dissector support. > > What logic does Wireshark use to

Re: [Wireshark-users] MPLS over UDP decoding

2018-12-27 Thread Hugo van der Kooij
I would say this is a rather impossible question. Your configuration is a relevant factor. As is the actual packet data. With neither of them available it is impossible to answer. But in general disable not relevant protocols in the profile you use. I use various profiles where I disable not