Wireshark
MDIF messages sent over Ethernet (not serial via HDLC) can be captured and
decoded using the Wireshark network protocol analyzer. The MDIF dissector is not
included in the standard Wireshark distribution, but can be setup as a plugin.
The plugin is available in this package in the form of the Lua script
src/wireshark/create_mdif_dissector.lua
.
Setup
The Lua script to create the MDIF dissector should be placed in the folder for personal Lua plugins. The location of this folder can be found in the “About Wireshark” dialog under the “Help” menu. Choose “Folders” and look for the location of “Personal Lua Plugins”.
data:image/s3,"s3://crabby-images/bd786/bd786dbd4de97accc4a1037efe88ef9b34fa9f2d" alt="_images/about_folders.png"
Next configure the Protobuf search paths to include the MDIF message
definitions. The protobuf definitions are available in this package in the
folder src/protobuf
. Structure of base files look like this:
src/protobuf
└── mdif
├── common.proto
├── core
│ └── core.proto
├── fwu
│ └── fwu.proto
└── rfs
└── rfs.proto
The Protobuf search paths should be set to include the folder where the :file: mdif folder is located. Setup is done in Edit –> Preferences –> Protocols –> ProtoBuf:
data:image/s3,"s3://crabby-images/f290a/f290acb14499775dae8804c657445bfa7ed7017b" alt="_images/protobuf_setup.png"
Tick the options shown above and then edit the search paths to include the folder
containing the mdif
folder.
data:image/s3,"s3://crabby-images/c2bab/c2babb120d9bb41dcf1d2f4ede7e3b606486fd75" alt="_images/search_paths.png"
Finally, setup decoding of traffic to/from port 21020 to use the MDIF dissector. Open the “Decode as…” dialog from the “Analyze” menu, and add an entry like this:
data:image/s3,"s3://crabby-images/872d3/872d32c50f692d4b271ad2325b828da327c4381e" alt="_images/decode_as.png"
Decoding of MDIF messages should now be possible:
data:image/s3,"s3://crabby-images/0d565/0d565f6b688af75611eb0f94f2173b978f48e06c" alt="_images/decoding.png"