Differences between revisions 2 and 3
Revision 2 as of 2006-07-23 21:20:35
Size: 1698
Editor: h141n1fls34o887
Comment:
Revision 3 as of 2008-04-12 17:50:27
Size: 1706
Editor: localhost
Comment: converted to 1.6 markup
Deletions are marked like this. Additions are marked like this.
Line 11: Line 11:
 * ["TCAP"]/["SCCP"]: Typically, CAMEL uses ["TCAP"]/["SCCP"] as its transport protocol. The ssn used to dissect CAMEL is configurable.  * [[TCAP]]/[[SCCP]]: Typically, CAMEL uses [[TCAP]]/[[SCCP]] as its transport protocol. The ssn used to dissect CAMEL is configurable.
Line 29: Line 29:
 * attachment:SampleCaptures/PROTO.pcap  * [[attachment:SampleCaptures/PROTO.pcap]]
Line 32: Line 32:
A complete list of PROTO display filter fields can be found in the [http://www.wireshark.org/docs/dfref/protofirstletter/proto.html display filter reference] A complete list of PROTO display filter fields can be found in the [[http://www.wireshark.org/docs/dfref/protofirstletter/proto.html|display filter reference]]
Line 39: Line 39:
You cannot directly filter PROTO protocols while capturing. However, if you know the ["TCP"] port used (see above), you can filter on that one. You cannot directly filter PROTO protocols while capturing. However, if you know the [[TCP]] port used (see above), you can filter on that one.
Line 47: Line 47:
 * [http://www.ietf.org/rfc/rfc123.txt RFC 123] ''The RFC title'' - explanation of the RFC content.  * [[http://www.ietf.org/rfc/rfc123.txt|RFC 123]] ''The RFC title'' - explanation of the RFC content.

Customised Applications for Mobile network Enhanced Logic (CAMEL)

CAMEL is based on a sub-set of the ETSI Core INAP CS-2 as specified by EN 301 140-1

History

Protocol dependencies

  • TCAP/SCCP: Typically, CAMEL uses TCAP/SCCP as its transport protocol. The ssn used to dissect CAMEL is configurable.

Example traffic

XXX - Add example decoded traffic for this protocol here (as plain text or Wireshark screenshot).

Wireshark

The CAME dissector is fully functional.

Preference Settings

(XXX add links to preference settings affecting how PROTO is dissected).

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here (see below). Keep this file short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.

Display Filter

A complete list of PROTO display filter fields can be found in the display filter reference

  • Show only the PROTO based traffic:

     proto 

Capture Filter

You cannot directly filter PROTO protocols while capturing. However, if you know the TCP port used (see above), you can filter on that one.

  • Capture only the PROTO traffic over the default port (80):

     tcp port 80 

  • add link to PROTO specification and where to find additional info on the web about it, e.g.:
  • RFC 123 The RFC title - explanation of the RFC content.

Discussion

CAMEL (last edited 2008-04-12 17:50:27 by localhost)