WiresharkIntegration » History » Version 4

« Previous - Version 4/11 (diff) - Next » - Current version
laforge, 02/19/2016 10:49 PM
add note about the udp port / icmp reject

= Wireshark integration =

[ wireshark] is a popular Open Source protocol analyzer. Among many
other protocols, it includes dissectors for the GSM Layer 2 (LAPDm) and 3 (04.08).

There also is a [wiki:GSMTAP] protocol dissector in recent wireshark versions, which allows
real-time capture and decode of GSM protocol messages encapsulated in a GSMTAP (pseudo-header,
which is in turn encapsulated in UDP and IP).

So if you have a wireshark version with [wiki:GSMTAP] support, you can have real-time decode and
trace of GSM protocol messages.

The OsmocomBB [wiki:layer23] program sends [wiki:GSMTAP] packets to the localhost ( address
of the loopback interface (lo). Please note that the wireshark program is doing passive capture,
i.e. if nothing is listening on the [wiki:GSMTAP] UDP port (4729), then you will see ICMP port unreachable
messages in addition to the GSMTAP messages. There are two suggested solutions to this: * Change the IP address to a multicast group like (instead of * Run some program that simply opens the UDP port and discards its content, e.g. using {{{{nc -u -l -p 4729 > /dev/null}}}


Image(gsmtap-wireshark.png, 66%)

Add picture from clipboard (Maximum size: 48.8 MB)