Wireshark mailing list archives
save decrypted ESP
From: tsaitgaist <ml () mail tsaitgaist info>
Date: Thu, 03 Mar 2011 18:21:49 +0100
Hi, I putted the keys for ESP (IPsec) traffic in wireshak using the menu. It was able to decrypte and show the encrypted payload. But saving the file only saves the encrypted packets. I also used tshark with the appropriate -o option. Again it can decrypted and show me the payloads, but does not save the decypted "packets". tcpdump offers a way to decode ESP traffic, but it does not support aes-128-cbc. Is there any way to save the decrypted packets ? Thanks, kevin ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- save decrypted ESP tsaitgaist (Mar 04)