Siemens PLC Packets - Showing COTP instead of S7COMM [closed]
Hi, my Wireshark displays the Siemens PLC communication (with HMI) packets as COTP instead of S7COMM. How can I see the packets in S7COMM format?
Looking forward to the answers, please...
There are S7COMM Sample Captures on the Wireshark wiki that contain both
COTP
andS7COMM
frames.If those display properly for you then maybe an issue with your capture files. If they don't display, we can dig into what needs to be configured for your instance of Wireshark.
Hi Chucks. Thanks for attending to this question. I think the captured packets are good. the issue is with the configuration/setting in my Wireshark. I can see the protocol as S7COMM when I open this Wireshark backup from another PC.
Are both systems running the same version of Wireshark?
Have you tried copying over a known good profile from the working system?
Yes, both systems run the same version of Wireshark. It was displaying the protocol as S7COMM on my PC. I have made some changes in the Wireshark settings. The protocol displays as COTP instead of S7COMM after this change. Unfortunately, I cannot recall which settings I changed.