cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
826
Views
0
Helpful
4
Replies

ASA packet capture query

CiscoNutt
Level 1
Level 1

I have a packet capture output and am wondering about the number (46) that comes after udp.  What does this indicate?  I can find no reference to it in wireshark.

1: 08:35:39.635251       802.1Q vlan#9 P0 10.3.2.7.63325 > 146.112.61.107.53:  udp 46 

1 Accepted Solution

Accepted Solutions

"46" is the length of the packet that got captured.

View solution in original post

4 Replies 4

Vishnu Sharma
Level 1
Level 1

What are these two Ip addresses " 10.3.2.7 & 146.112.61.107"?

The traffic is going on UDP port 53. It can be DNS server or traffic from Xbox Live.

Thanks,

Vishnu

I know what the traffic is I was just curious as to the number after UDP which Karsten has answered for me.

Just FYI, the traffic is generated by a trojan (torrentlocker)

"46" is the length of the packet that got captured.

Ok.  Thanks, odd thing is that in Wireshark the length is shown as 54, so I can only assume that wireshark shows an 8 bit header aswell?

Review Cisco Networking products for a $25 gift card