CIP I/O Packets Displayed Differently
I'm reviewing a capture I was sent recently. I have packets in the same capture of the same protocol (CIP I/O) which are displaying differently. One shows details and separates out the 32-bit header and one does not.
I think maybe they are being dissected differently? How do I confirm? Then, why are packets of the same protocol dissecting differently?
I'm unable to upload the photo so please see the two examples below:
(with details)
Common Industrial Protocol, I/O
CIP Sequence Count: 2
32-bit Header: 0x00000021, Run/Idle: Run
.... .... .... .... .... .... .... 00.. = ROO: 0x0
.... .... .... .... .... .... .... ..0. = COO: 0x0
.... .... .... .... .... .... .... ...1 = Run/Idle: Run (0x1)
Data: 0000
(without details)
Common Industrial Protocol, I/O
CIP Sequence Count: 0
Data: 210000000000