EAPS is a proprietary protocol developed by Extreme Networks to help with the "availability and robustness of Ethernet rings". EAPS was designed specifically to support implementing a fast resilient layer 2 physical loop topology without having to depend on the traditional Spanning Tree based protocols.
XXX - Add more info about what EAPS is here.
Version 1 of EAPS was publically documented in October 2003 as RFC3619. The EAPS Frame format documented within RFC3619 indicates that the EAPS "TLV" starts at offset 0x32 of the frame. But actual EAPS data seen in captures implies that EAPS has evolved and is now encapsulated within EDP (Extreme Discovery Protocol) packets.
VLAN: EAPS control data is passed on 802.1Q control VLAN.
XXX - Add example traffic here (as plain text or Wireshark screenshot).
EAPS dissection is implemented within the EDP dissector. Consequently all the EAPS specific fields are accessed as edp.eaps.XXX
A complete list of EAPS display filter fields can be found under the Extreme Discovery Protocol (EDP) in the display filter reference
This following filter will select out just EAPS frames (and exclude other EDP frames):
Because EAPS is encapsulated within EDP, one can not specifically capture EAPS frames. But because EAPS packets are contained within EDP packets and these specific EDP packets are sent to the destination MAC address 00.e0.2b.00.00.04 one can specifically capture EAPSv1 frames.
Capture only the EAPS traffic:
ether dest 0:e0:2b:0:0:4
add link to EAPS specification and where to find additional info on the web about it, e.g.:
RFC 3619 Extreme Networks Ethernet Automatic Protection Switching (EAPS) Version 1.
XXX - Add some notes here regarding some observations regarding EAPS.
Subsequent to the release of Wireshark 0.10.12, support for EDP/EAPS was initially added in August 2005 (starting with SVN 15299).
Imported from https://wiki.wireshark.org/EAPS on 2020-08-11 23:13:42 UTC