How to decrypt Ipsec protocol that have esp with command line

asked 2018-11-14 08:26:35 +0000

Hello, I work with wireshark a lot and I need to decode a LOT of traces that have ESP. It takes a long time to manually enter in all the information necessary in the GUI to decode each different trace, so I am trying to figure out a way to pass the ESP decryption parameters as command line arguments to tshark or wireshark. Or even be able to edit a file like esp_sa.

Thanks, surya

answered 2018-11-15 22:04:38 +0000

If you have messages in your traces that describe the SPI/keys, you could write a dissector for those messages and call esp_sa_record_add_from_dissector()(see

Asked: 2018-11-14 08:26:35 +0000

