First time here? Check out the FAQ!
THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.
0

Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?

Can wireshark be set up to differentiate if a QUIC pcap is GQUIC or IETF QUIC?

jvthird's avatar
1
jvthird
asked 2022-05-05 21:39:03 +0000
edit flag offensive 0 remove flag close merge delete

Comments

add a comment see more comments

1 Answer

0

Maybe.
View->Internals->Dissector Tables then search on "quic".
GQUIC and QUIC are registered as udp Heuristics.
From the WSUG (User's Guide):

As Wireshark tries to find the right dissector for each packet (using static “routes” and heuristics “guessing”), it might choose the wrong dissector in your specific case.

Wireshark makes a SWAG and does it's best.

There are captures attached to 13881 - Add (IETF) QUIC Dissector and 15984 - gquic parser Q046 support that show each protocol dissected.

Chuckc's avatar
3k
Chuckc
answered 2022-05-06 13:20:03 +0000
edit flag offensive 0 remove flag delete link

Comments

add a comment see more comments

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account. This space is reserved only for answers. If you would like to engage in a discussion, please instead post a comment under the question or an answer that you would like to discuss.

Add Answer