How to decode a packet received through WireShark and resolve some errors

We collect traffic using JN5148EK010 nodes through WireShark. Received packets are shown in the screenshot.

  • I want to know how to decode data.
  • An error occurred while capturing multiple packets whose screenshot is also provided. How to fix this error?
  • List item

Another error occurred (see the third screenshot).

How to resolve this?

enter image description hereenter image description here

enter image description here

+6
source share
2 answers

A quick web search suggests that Wireshark is used with custom plugins (provided by Jennic?).

The Jennic Sniffer Protocol string was not found in the current Wireshark sources, which strongly indicates that a custom version of Wireshark is being used.

So: I suspect that you will need to consult the seller and / or the vendor documentation (in which I mention various configuration options).


In any case, it is almost impossible to say much without being able to analyze the actual capture; based only on screenshots, I will just say the following.

The expert window says: "We do not support encryption with the protocol [version?]"

Does this apply to frame 322 that you selected. If so, the message means only what he says (assuming that the attempted autopsy is valid).

“incorrect” messages mean that the dissector cannot comprehend the data.

Larger image: Given the various “irregular shapes” and the warning that decryption is not supported, anything is possible ...

Again, your best approach may be to consult with the seller.

0
source

Screenshots of Wireshark show that you have been using Wireshark 1.6.5 (or a customized version based on Wireshark 1.6.5), which is over 5 years old. According to the Wireshark Lifecycle page, support for Wireshark 1.6 ended on June 7, 2013.

Since then, there have been many updates to the IEEE 802.15.4 dissector , and there may be a very good chance that the updated dissector will analyze the data you are interested in.

I would recommend you upgrade your version of Wireshark .

0
source

All Articles