how to dissect X711 CMIP traffic ?

asked Dec 15 '2

kiwi123 gravatar image

updated Dec 23 '2

Hi, i'm using wireshark version 3.4.10 on debian 11 and i don't manage to decode traffic as X711 CMIP traffic. I've checked in Analyze->Protocol->Activated Protocols, and CMIP is activated, so i suppose Wireshark should be able to decode my traffic as CMIP traffic.

I thought maybe this traffic requires another dissector to be activated therefore i activated all the dissectors. Even with that, when i right click on a packet, the "decode as" menu doesn't propose CMIP protocol.

It seems that X711/CMIP protocol is transported by ACSE or ROSE protocol (which are in their turn over TCP), but it doesn't seem to exist dissector for such protocol in wireshark.

Am i missing something ?

link to pcap

Preview: (hide)

Comments

Can you share a capture file?

Chuckc gravatar imageChuckc ( Dec 15 '2 )

This trace https://wiki.wireshark.org/uploads/__... shows some of those transport layers.

Anders gravatar imageAnders ( Dec 15 '2 )

So maybe decode as TPKT on TCP level?

Anders gravatar imageAnders ( Dec 15 '2 )

Hi, thx for your anwser, unfortunately i can't upload any capture (my karma is too low !).

kiwi123 gravatar imagekiwi123 ( Dec 20 '2 )

Place it on public file share (Dropbox, Google, OneDrive) then update the question with a link to it.

Chuckc gravatar imageChuckc ( Dec 20 '2 )