Wireshark mailing list archives

save decrypted ESP


From: tsaitgaist <ml () mail tsaitgaist info>
Date: Thu, 03 Mar 2011 18:21:49 +0100

Hi,

I putted the keys for ESP (IPsec) traffic in wireshak using the menu.
It was able to decrypte and show the encrypted payload.
But saving the file only saves the encrypted packets.
I also used tshark with the appropriate -o option.
Again it can decrypted and show me the payloads, but does not save the
decypted "packets".
tcpdump offers a way to decode ESP traffic, but it does not support
aes-128-cbc.
Is there any way to save the decrypted packets ?

Thanks,
kevin
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: