Tuesday, December 5, 2017

Wireshark display filter for Radius-traffic

Hi!

I'm troubleshooting an authentication/Radius issue and I have a Wireshark PCAP of the traffic. So far so good. What I want to achieve now is to be able to filter (with a display filter) all traffic for a specific login session.

So basically what I'm looking for is something in a Radius packet that I can filter on that will show all packets (access-request, access-challenge, access-reject and access-accept) for a specific user.

I've tried to filter on everything in the AVP fields without success. I tried to filter on "Packet Identifier" but that does not seem to be unique. I still se radius packets from other users.

Anyone have any good ideas on what I can filter on so the troubleshooting process gets a little bit cleaner and easier?



No comments:

Post a Comment