Hi,

I have a problem with analyzing SCTP traffic with many chunks in one SCTP packet - for example in one SCTP packet I have chunks with BSSAP RANAP GSM MAP and ISUP. When I select display filter BSSAP I see all SCTP packets which contains BSSAP packets - but to see for example call flow on BSSAP transaction it is impossible because each SCTP packets contains more chunks with BSSAP data.

Is there any possibility to enable functionality that allows me to clone SCTP packets with only one chunk to see every chunk in new line - now I have few chunks in SCTP packet in one row.

Best Regards Tom (tomasz.ejsmont@telekomunikacja.pl)

asked 11 May '11, 06:20

alluryn's gravatar image

alluryn
1222
accept rate: 0%

edited 11 May '11, 08:42

cmaynard's gravatar image

cmaynard ♦
3.2k51656


Unfortunately, no.

One solution was discussed many years ago, but it has not been worked on.

link

answered 11 May '11, 09:37

JeffMorriss's gravatar image

JeffMorriss ♦
2.2k432
accept rate: 25%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×10
×2

Asked: 11 May '11, 06:20

Seen: 1,358 times

Last updated: 11 May '11, 09:37

powered by OSQA