How do I filter/capture/read packets of one protocol embedded in another?
I'm trying to read a tapped line (using a Tap Aggregator) for the DNP traffic, but it appears to all be embedded in the TCP packets, so the filter isn't showing anything when I filter for dnp3.
How do I borg down another level in Wireshark?
There are dnp3 display filters for sure. Are you talking about filtering during the capture itself?
The dnp3 filter isn't seeing the dnp in the packets. I'm going to look into the port being referenced as per the one answer given.