Ethernet header after MPLS starts with a 6 and being decoded as IPv6 [closed]

  • retag add tags

I have a capture where I have packets with MPLS followed by destination/source mac addresses of the underlying Ethernet traffic. However, the destination mac address starts with a 6, which Wireshark decodes as an IPv6 header. How can I get it to recognize this as an Ethernet header?

rgonzo66's avatar
1
rgonzo66
asked 2022-09-02 00:17:36 +0000
edit flag offensive 0 remove flag reopen merge delete

Closed for the following reason "the question is answered, right answer was accepted" by rgonzo66 2022-09-02 13:50:46 +0000

Comments

Can you post the capture on a public share and then add a link to it back here?

grahamb's avatar grahamb (2022-09-02 07:55:46 +0000) edit

Unfortunately there's no good heuristic to determine if the MPLS payload starts with an Ethernet frame, IP or other protocol. There are/were a bunch of open bugs on this subject. Maybe I can dig something up, when I find some time.

Jaap's avatar Jaap (2022-09-02 10:53:58 +0000) edit

Here is a link to the capture. [https://drive.google.com/file/d/1ZRde...]

rgonzo66's avatar rgonzo66 (2022-09-02 12:58:32 +0000) edit

Excellent. That is my problem. Thank you.

rgonzo66's avatar rgonzo66 (2022-09-02 13:49:55 +0000) edit
add a comment see more comments