2020-06-24 15:27:32 +0000 | commented answer | reference outer most eth.type final filter is as follows -Y "frame.protocols ~ \"^eth:ethertype:ip:tcp\" or frame.protocols ~ \"^eth:ethertype:vlan: |
2020-06-24 09:29:44 +0000 | commented answer | reference outer most eth.type perhaps if you can do some minior regex like searching, you could do some pretty interesting filtering e.g frame.proto |
2020-06-24 09:20:06 +0000 | commented answer | reference outer most eth.type a better way is partial string frame.protocols ~ eth:ethertype:ip:tcp otherwise it only counts tcp packets it cant dec |
2020-06-24 08:10:56 +0000 | commented answer | reference outer most eth.type looks like we can do it this way frame.protocols == eth:ethertype:ip:tcp |
2020-06-23 12:57:07 +0000 | marked best answer | reference outer most eth.type Is there any way to reference the outer most eth.type value in a display filter? e.g. we are filtering on eth.type == 0x0800 (ipv4) packets. Because some packets are encapsulated with another ethernet header the display filter is matching on both outer and inner ethernet frames. Our specific goal is to filter on the outer most ethernet frame. heres the display filter eth.type == 0x0800 and ip.proto == 6 and tcp.option_kind==5 Example packet in question Edit 1: Looking at this some more, the display filter is working ... (more) |
2020-06-23 12:57:07 +0000 | received badge | ● Scholar (source) |
2020-06-23 12:57:04 +0000 | received badge | ● Supporter (source) |
2020-06-23 12:57:02 +0000 | commented answer | reference outer most eth.type Thanks, sounds need a different approach |
2020-06-22 17:02:03 +0000 | edited question | reference outer most eth.type reference outer most eth.type Is there any way to reference the outer most eth.type value in a display filter? e.g. we |
2020-06-22 17:01:37 +0000 | received badge | ● Rapid Responder (source) |
2020-06-22 17:01:37 +0000 | answered a question | reference outer most eth.type Looking at this some more, the display filter is working as the outer level Eth protocol is IPv4. Hmm.. guess referencin |
2020-06-22 16:54:33 +0000 | edited question | reference outer most eth.type reference outer most eth.type Is there any way to reference the outer most eth.type value in a display filter? e.g. we |
2020-06-22 16:54:15 +0000 | received badge | ● Editor (source) |
2020-06-22 16:54:15 +0000 | edited question | reference outer most eth.type reference outer most eth.type Is there any way to reference the outer most eth.type value in a display filter? e.g. we |
2020-06-22 16:34:15 +0000 | asked a question | reference outer most eth.type reference outer most eth.type Is there any way to reference the outer most eth.type value in a display filter? e.g. we |