Ethernet header after MPLS starts with a 6 and being decoded as IPv6 [closed]

asked 2022-09-02 00:17:36 +0000

I have a capture where I have packets with MPLS followed by destination/source mac addresses of the underlying Ethernet traffic. However, the destination mac address starts with a 6, which Wireshark decodes as an IPv6 header. How can I get it to recognize this as an Ethernet header?

edit retag flag offensive reopen merge delete

Closed for the following reason the question is answered, right answer was accepted by rgonzo66
close date 2022-09-02 13:50:46.000953

Comments

Can you post the capture on a public share and then add a link to it back here?

grahamb gravatar imagegrahamb ( 2022-09-02 07:55:46 +0000 )edit

Unfortunately there's no good heuristic to determine if the MPLS payload starts with an Ethernet frame, IP or other protocol. There are/were a bunch of open bugs on this subject. Maybe I can dig something up, when I find some time.

Jaap gravatar imageJaap ( 2022-09-02 10:53:58 +0000 )edit

Here is a link to the capture. [https://drive.google.com/file/d/1ZRde...]

rgonzo66 gravatar imagergonzo66 ( 2022-09-02 12:58:32 +0000 )edit

Excellent. That is my problem. Thank you.

rgonzo66 gravatar imagergonzo66 ( 2022-09-02 13:49:55 +0000 )edit