This wiki has been migrated to and is now deprecated. Please use that site instead.

Network Data Management Protocol (NDMP)

NDMP is a protocol to manage network backups for mid and enterprise class environments.


NDMP was initially developed by the storage vendor Network Appliance but has since gained popularity in the industry and is now developed jointly by some industry vendors.
There are 4 popular versions of NDMP in use today, versions 2, 3, 4 and 5.

Protocol dependencies

Example traffic

C:\ndmp-config-get-auth-attr-reply.png ndmp-connect-client-auth-request.png


The dissector has full support for version 2 of NDMP. This version is also the default version in Wireshark.
Wireshark also contains a dissector for the SCSI protocol(s) which allows dissection of the SCSI payload for those NDMP commands that transport raw scsi.
Wireshark has limited and very likely incomplete support for the changes in the protocol added after version 2.

Please help wireshark become better at dissecting NDMP by donating example captures of non- version 2 uses and patches to the sourcecode to implement more of version 3, 4 and 5.

Preference Settings

See NDMP_Preferences.

Example capture file

* SampleCaptures/ndmp.pcap.gz

Display Filter

A complete list of NDMP display filter fields can be found in the display filter reference

Capture Filter

You cannot directly filter NDMP protocols while capturing. However, if you know the TCP port used (see above), you can filter on that one.


Network_Data_Management_Protocol (last edited 2008-04-12 17:51:38 by localhost)