SCTP PPID = 206 unknown, what type of protocol is used next? [closed]

asked 2023-01-16 10:31:05 +0000

Hello, I have the STCP protocol and its PPID = 206, for wireshark and for iana this protocol is not assigned. The payload always starts with (0x00, 0x01, 0x02, 0x03), I think the second byte 0x00 is service information or 0x01 is useful information, the length of the packet is 3-4 bytes. Tell me what type of protocol can be used after SCTP. Ports for SCTP are 30 and 14596. 002145c000486e344000ff84d8f20a7300010a731e643904001e266587833b7b0cb500030027dd886dff000098f2 000000ce 01000013dc07082975401012096956560a000cc0b229a300 000000ce - 206 PPID.

Can you share a capture file on a public file share then add a link to it?

Chuckc gravatar imageChuckc ( 2023-01-16 16:41:45 +0000 )edit

Thanks, I figured it out myself yesterday. If you take decode as... and select SCTP PPID, then more available protocols appear, selected LAPD and was able to expand.

CamperoK gravatar imageCamperoK ( 2023-01-17 12:07:23 +0000 )edit