Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?
Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?
Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?
Maybe.
View->Internals->Dissector Tables
then search on "quic".
GQUIC
and QUIC
are registered as udp Heuristics.
From the WSUG (User's Guide):
As Wireshark tries to find the right dissector for each packet (using static “routes” and heuristics “guessing”), it might choose the wrong dissector in your specific case.
Wireshark makes a SWAG and does it's best.
There are captures attached to 13881 - Add (IETF) QUIC Dissector and 15984 - gquic parser Q046 support that show each protocol dissected.
Please start posting anonymously - your entry will be published after you log in or create a new account.
Asked: 2022-05-05 21:39:03 +0000
Seen: 257 times
Last updated: May 06 '22