Ask Your Question

tlemons's profile - activity

2023-11-27 21:58:33 +0000 received badge  Rapid Responder
2023-11-27 21:58:33 +0000 answered a question Wireshark doesn't see packets when just one system is 'local'

Hi Andre - thanks for the reply. Yes, I believe a distributed port group is essentially a switch. I'm trying to capture

2023-11-27 20:05:36 +0000 asked a question Wireshark doesn't see packets when just one system is 'local'

Wireshark doesn't see packets when just one system is 'local' Hi Wireshark is not 'seeing' / capturing all of the packe

2021-11-09 16:16:05 +0000 received badge  Famous Question (source)
2019-08-06 19:25:34 +0000 received badge  Famous Question (source)
2019-04-19 16:11:25 +0000 received badge  Notable Question (source)
2018-11-08 12:37:16 +0000 received badge  Notable Question (source)
2018-11-08 12:37:16 +0000 received badge  Popular Question (source)
2018-10-25 05:30:49 +0000 received badge  Popular Question (source)
2018-04-16 18:31:29 +0000 commented answer Can Wireshark decode a LDAPs conversation?

That worked great! I had fiddled with this, but had not used these values: Field - SSL Port Value - 636 Type - Integer,

2018-04-16 18:28:50 +0000 marked best answer Can Wireshark decode a LDAPs conversation?

I captured a 'regular' (no TLS) LDAP conversation and Wireshark decoded the LDAP conversation.

I captured a LDAPs conversation and, because I had the private key of the server, Wireshark was able to decode the TCP packets and show the data inside them.

But Wireshark was not able to decode / display the LDAP conversation inside the decrypted TCP packets. Should Wireshark have been able to do this, and I just didn't set it up correctly?

Thanks! tl

2018-04-16 18:28:50 +0000 received badge  Scholar (source)
2018-04-13 03:10:53 +0000 asked a question Can Wireshark decode a LDAPs conversation?

Can Wireshark decode a LDAPs conversation? I captured a 'regular' (no TLS) LDAP conversation and Wireshark decoded the L

2018-03-30 18:54:12 +0000 commented answer How can I decode TLS that uses DH?

Thank you for this explanation!

2018-03-30 15:14:30 +0000 edited question How can I decode TLS that uses DH?

How can I decode TLS that uses DH? I regularly capture and analyze exchanges involving data protection applications that

2018-03-30 15:14:13 +0000 received badge  Editor (source)
2018-03-30 15:14:13 +0000 edited question How can I decode TLS that uses DH?

How can I decode TLS that uses DH? I regularly capture and analyze exchanges involving data protection applications that

2018-03-30 15:10:59 +0000 asked a question How can I decode TLS that uses DH?

How can I decode TLS that uses DH? I regularly capture and analyze exchanges involving data protection applications that

2017-12-13 14:43:55 +0000 commented answer RabbitMQ/amqp not decoded

My problem there is the capture file shows company confidential information, and I'm not sure how to sanitize it. What's

2017-12-10 05:58:07 +0000 commented answer RabbitMQ/amqp not decoded

Thanks for that information. I've found that one of the RabbitMQ conversations in our tests is not using TLS (it will so

2017-12-07 15:40:47 +0000 commented answer RabbitMQ/amqp not decoded

That worked great, thanks for the suggestion! 'Forcing' port 5671 to use the SSL decoder allowed me to see that the clas

2017-12-07 04:39:00 +0000 commented answer RabbitMQ/amqp not decoded

Thanks you for this explanation. I've reviewed the Wireshark SSL information. Last question: I know that Wireshark could

2017-12-06 15:03:29 +0000 asked a question RabbitMQ/amqp not decoded

RabbitMQ/amqp not decoded Hi - I'm using Wireshark v2.4.2 to display and decode a RabbitMQ exchange between two systems.