Ask Your Question

PktN00bie's profile - activity

2020-12-17 20:07:28 +0000 received badge  Popular Question (source)
2020-01-13 07:34:44 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Sorry for the late response. Here is the link to the dumped analyze result txt file. Some major difference is like pack

2020-01-13 07:27:45 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Sorry for the late response. Here is the link to the dumped analyze result txt file. Some major difference is like pack

2020-01-13 07:26:25 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Sorry for the late response. Here is the link to the dumped analyze result txt file. Some major difference is like pack

2020-01-13 07:25:54 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Sorry for the late response. Here is the link to the dumped analyze result txt file. Some major difference is like pack

2020-01-13 07:18:31 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Sorry for the late response. Here is the link to the dumped analyze result txt file. Now I see that in the results it sa

2020-01-03 18:11:52 +0000 marked best answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

I recently got a device that claimed it's using Zigbee technology to transmit data and I was to do some testing on it. Problem is, when I tried sniffing the data transmitted, wireshark showed its protocol as LwMesh (LightWeight Mesh).

I did some research and apparently LwMesh also follow IEEE 802.15.4 for its PHY/MAC layer. Only that LwMesh lack some higher level features of Zigbee. Now we are having a debate about if this thing really should be treated as a Zigbee device. (Because the test items may differ.)

LwMesh and Zigbee are so similar to each other that we are afraid that it may be wireshark determining the protocol incorrectly.

Apart from the fact that this device does not get certified by Zigbee alliance, we need more evidence or proof to know if it really is using Zigbee or LwMesh as its network layer protocol.

I tried to look for a way to understand how wireshark tell apart protocols but to no avail. It seems like it's not by looking for some specific bytes or bits in a 802.15.4 frame. It will be really great if I can get more insight into how to determine packet protocol correctly.

This is the link to the pcap file we captured.
https://drive.google.com/open?id=1qKBxrdIVHSYbRr_cSd7QwFaEUNlEvZa4

2020-01-03 18:11:52 +0000 received badge  Scholar (source)
2020-01-03 18:11:41 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

@ grahamb I had sniffed some traffic from Zigbee certified devices before and Wireshark did automatically dissect them

2020-01-03 16:17:52 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Thanks for you guys' answer ! After I posted this question, we even get out hands on a PC with Ubiqua Packet Analyzer a

2020-01-03 16:17:32 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Thanks for you guys' answer ! After I posted this question, we even get out hands on a PC with Ubiqua Packet Analyzer an

2020-01-03 16:14:01 +0000 commented answer Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Thanks for you guys' answer ! Since the heuristic is weak, I guess it will be more proper to change my question into "Wh

2020-01-02 10:40:35 +0000 asked a question Are there any chance for wireshark to determine 802.15.4 protocols incorrectly?

Are there any chance for wireshark to determine 802.15.4 protocols incorrectly? I recently got a device that claimed it'