This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Troubleshooting SCTP packets on IPSec Tunnels

1

Hi,

I would like to know if there is any mechanism to decrypt and analyze the SCTP packets exchanged over IPSec tunnels between two end nodes, for troubleshooting using Wireshark or tshark?

Please advise.

Regards, SC

asked 22 Dec '13, 20:23

tintin's gravatar image

tintin
26113
accept rate: 0%


One Answer:

0

Try it by setting preferences for ESP option. Regards, NA

answered 22 Dec '13, 23:01

alaska's gravatar image

alaska
1
accept rate: 0%

In other words, you have to configure Wireshark to decode the IPSec; after that then it will analyze whatever the IPSec payload as normal. See the wiki for more details.

(23 Dec '13, 07:21) JeffMorriss ♦

One-upping this question because I suspect in the next couple quarters it's going to be a popular need in mobile. IPX and Diameter is coming. :)

(26 Dec '13, 07:23) Quadratic