Ask Your Question
0

Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?

asked 2022-05-05 21:39:03 +0000

Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?

edit retag flag offensive close merge delete

1 Answer

Sort by » oldest newest most voted
0

answered 2022-05-06 13:20:03 +0000

Chuckc gravatar image

Maybe.
View->Internals->Dissector Tables then search on "quic".
GQUIC and QUIC are registered as udp Heuristics.
From the WSUG (User's Guide):

As Wireshark tries to find the right dissector for each packet (using static “routes” and heuristics “guessing”), it might choose the wrong dissector in your specific case.

Wireshark makes a SWAG and does it's best.

There are captures attached to 13881 - Add (IETF) QUIC Dissector and 15984 - gquic parser Q046 support that show each protocol dissected.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2022-05-05 21:39:03 +0000

Seen: 257 times

Last updated: May 06 '22