| Main Archive Page > Month Archives > wireshark-dev archives |
these packets run directly atop IP, any suggestions?
Thanks
> From: guy@alum.mit.edu
> Date: Sun, 26 Jun 2011 13:48:07 -0700
> To: wireshark-dev@wireshark.org
> Subject: Re: [Wireshark-dev] why cannot I use heur_dissector_add("ip", .....
>
>
> On Jun 26, 2011, at 1:44 PM, John x wrote:
>
> > Yes it is that TTL changes in-flight. But my packets are captured on a specific link, there are only 2 or 3 kinds of packets. The way to distinguish them is only the TTL value.
>
> So these packets run *directly* atop IP?
>
> Or do they run atop UDP or TCP or some other protocol?
> ___________________________________________________________________________
> Sent via: Wireshark-dev mailing list <wireshark-dev@wireshark.org>
> Archives: http://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
> mailto:wireshark-dev-request@wireshark.org?subject=unsubscribe
___________________________________________________________________________
Sent via: Wireshark-dev mailing list <wireshark-dev@wireshark.org>
Archives: http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
mailto:wireshark-dev-request@wireshark.org?subject=unsubscribe