The NetBIOS Datagram Service is part of the NetBIOS-over-TCP protocol suite, see the NetBIOS page for further information.
XXX - add a brief description of NBDS history
- UDP: Typically, NBDS uses UDP as its transport protocol. The well known UDP port for NBDS traffic is 138.
XXX - Add example traffic here (as plain text or Wireshark screenshot).
The NBDS dissector is partially functional; it should dissect all of the protocol, but does not reassemble datagrams fragmented at the NBDS layer.
(XXX add links to preference settings affecting how NBDS is dissected).
XXX - Add a simple example capture file to the SampleCaptures page and link from here. Keep it short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.
A complete list of NBDS display filter fields can be found in the display filter reference
Show only the NBDS based traffic:
You cannot directly filter NBDS while capturing. However, as it runs atop UDP port 138, you can filter on that port.
Capture NBDS traffic:
udp port 138
RFC1001 Protocol Standard For a NetBIOS Service on a TCP/UDP Transport: Concepts and Methods
RFC1002 Protocol Standard For a NetBIOS Service on a TCP/UDP Transport: Detailed Specifications
Imported from https://wiki.wireshark.org/NetBIOS/NBDS on 2020-08-11 23:17:12 UTC