Forum Discussion
Piotr_Lewandows
Apr 21, 2015Altostratus
Wireshark, F5 plugin and missing Low Details
Hi,
I am playing with Wireshark F5 plugin (great tool!!) and wonder why for some packets F5 Low Detail section is missing. Can't see pattern here.
I used this command to launch Wireshark:
plink.exe -l root -pw pass MGMT ip "tcpdump -w - -s0 -pi 0.0:nnn tcp or udp or icmp" | "c:\Program Files\Wireshark\wireshark.exe" -k -i -
Some packets have all levels, some not. I am using such Wireshark filter to track HTTP session:
(ip.addr eq 10.128.10.2 and ip.addr eq 10.128.10.40 and tcp.port eq 43685 and tcp.port eq 80) or (f5ethtrailer.peeraddr eq 10.128.10.2 and f5ethtrailer.peeraddr eq 10.128.10.40 and f5ethtrailer.peerport eq 43685 and f5ethtrailer.peerport eq 80 and (f5ethtrailer.peeripproto eq 6 or (f5ethtrailer.peeripproto eq 0 and tcp))) - actually it's created by Analyze -> Conversation Filter -> F5 TCP command in Wireshark
Here is capture:
Packet 686 has Low level
but packet 688 not
It happens for other packets but why - any idea?
Piotr
No RepliesBe the first to reply
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects