<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://linux-ax25.in-berlin.de/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=G1sog</id>
	<title>LinuxHam - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="http://linux-ax25.in-berlin.de/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=G1sog"/>
	<link rel="alternate" type="text/html" href="http://linux-ax25.in-berlin.de/wiki/Special:Contributions/G1sog"/>
	<updated>2026-04-19T16:44:46Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>http://linux-ax25.in-berlin.de/wiki?title=Wireshark&amp;diff=2410</id>
		<title>Wireshark</title>
		<link rel="alternate" type="text/html" href="http://linux-ax25.in-berlin.de/wiki?title=Wireshark&amp;diff=2410"/>
		<updated>2010-04-11T20:30:44Z</updated>

		<summary type="html">&lt;p&gt;G1sog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wireshark (formerly known as ethereal) is, along with [[tcpdump]], the prefered general purpose network protocol analyzer.  It's greatest disadvantage for the radio amateur was the lack of support for [[AX.25]], [[NETROM]] and [[ROSE]], so the only tool left was the special purpose tool listen(8) which pretty much only supports these protocols.&lt;br /&gt;
&lt;br /&gt;
= Initial release 2007-03-25 =&lt;br /&gt;
&lt;br /&gt;
Richard Stearn &amp;lt;richard@rns-stearn.demon.co.uk&amp;gt; has provided patches to add support for these protocols to libpcap, wireshark and tcpdump.  Below posting is mostly based on his announcements on [[linux-hams]] on 2007-03-18.&lt;br /&gt;
&lt;br /&gt;
For the foolhardy, desperate or those who just like to live dangerously.&lt;br /&gt;
:http://www.rns-stearn.demon.co.uk/ax25.wireshark.2007-03-25/&lt;br /&gt;
&lt;br /&gt;
These are source code patches.  The patches add to:&lt;br /&gt;
== libpcap ==&lt;br /&gt;
* recognition and capture of AX.25&lt;br /&gt;
&lt;br /&gt;
== tcpdump ==&lt;br /&gt;
* decoding AX.25&lt;br /&gt;
* extraction from BPQ&lt;br /&gt;
* decoding an ARP payload&lt;br /&gt;
* decoding a TCP/IP payload&lt;br /&gt;
* decoding NetROM&lt;br /&gt;
* recognition of Flexnet&lt;br /&gt;
* recognition of ROSE&lt;br /&gt;
&lt;br /&gt;
== wireshark ==&lt;br /&gt;
* dissection of AX.25&lt;br /&gt;
* extraction from BPQ&lt;br /&gt;
* extraction from AXIP (untested)&lt;br /&gt;
* dissection of ARP payload&lt;br /&gt;
* dissection of an TCP/IP payload&lt;br /&gt;
* dissection of NetROM&lt;br /&gt;
* recognition of Flexnet&lt;br /&gt;
* dissection of ROSE&lt;br /&gt;
* dissection of &amp;quot;No layer 3&amp;quot; payloads&lt;br /&gt;
** APRS (by the book)&lt;br /&gt;
** recognition of DX cluster&lt;br /&gt;
&lt;br /&gt;
The dissection of APRS &amp;amp; DX in wireshark is controlled via your preferences:&lt;br /&gt;
: Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;AX25 No L3&lt;br /&gt;
&lt;br /&gt;
All others are treated as having no L3 protocol and printed in hex and ascii.&lt;br /&gt;
&lt;br /&gt;
The patch is against:&lt;br /&gt;
: libpcap-0.9.5&lt;br /&gt;
: tcpdump-3.9.5&lt;br /&gt;
: wireshark-0.99.5&lt;br /&gt;
&lt;br /&gt;
= Update: 2010-04-10 =&lt;br /&gt;
&lt;br /&gt;
The Wireshark patch has been ported to wireshark-1.2.7 and can be found here:&lt;br /&gt;
:http://www.rns-stearn.demon.co.uk/ax25.wireshark.2010-04-10/&lt;br /&gt;
&lt;br /&gt;
The libpcap patch is now redundant as the necessary protocol identifiers have been added to libpcap-1.1 by the libpcap maintainers, so libpcap-1.1 is a pre-requisite to use of this patch.&lt;br /&gt;
&lt;br /&gt;
I have not yet ported the tcpdump patch.&lt;br /&gt;
&lt;br /&gt;
The main changes are the dissection of KISS &amp;amp; BPQ as separate protocols otherwise there is no change to the supported protocols.&lt;/div&gt;</summary>
		<author><name>G1sog</name></author>
	</entry>
</feed>