Ask Your Question
0

Wireshark Not Automatically Recognizing Some Modbus Traffic

asked 2022-06-17 14:38:15 +0000

What would cause Wireshark to not automatically recognize and decode Modbus TCP traffic? If I force it using Decode As and a port everything seems to look fine. The traffic appears to be compliant with the Modbus 1.1b specification.

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2022-06-17 18:24:43 +0000

grahamb gravatar image

updated 2022-06-17 18:40:36 +0000

The Modbus dissector is not heuristic so relies on traffic either running on the "standard" ports 502/tcp, 502/udp, 802/tls or the user configuring the dissector preferences for the port(s) actually used or using "Decode As..."

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2022-06-17 14:38:15 +0000

Seen: 401 times

Last updated: Jun 17 '22