You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wireshark 4.2.5:如何过滤GTPv2中cause=73的响应及对应请求包

Wireshark 4.2.5筛选GTPv2 Cause=73的CSResp及对应CSReq包

核心问题说明

直接用gtpv2.response_to == frame.number无法实现跨包关联过滤,因为Wireshark显示过滤无法直接引用其他包的字段值做匹配。以下是针对百万级数据包的高效解决方案:


方法1:导出字段批量生成过滤规则(无需脚本)

适合不想编写代码的场景,操作步骤如下:

  1. 先筛选目标响应包:在显示过滤栏输入
    gtpv2.msg_type == 257 && gtpv2.cause == 73
    
    注:257是CREATE SESSION RESPONSE的GTPv2消息类型编号,256是CREATE SESSION REQUEST的编号
  2. 导出response_to字段值:
    • 点击菜单栏「统计 > 导出字段」
    • 在字段列表中找到并添加gtpv2.response_to,选择导出格式为CSV
  3. 构造最终过滤规则:
    • 打开导出的CSV,提取所有包编号,整理成frame.number == 123 || frame.number == 456的格式
    • 将其与初始过滤规则合并,最终规则示例:
      (gtpv2.msg_type == 257 && gtpv2.cause == 73) || frame.number == 123 || frame.number == 456 || ...
      
    • 将合并后的规则输入显示过滤栏,即可同时显示所有目标响应包及对应请求包

方法2:Lua脚本自动标记(适合百万级数据包)

通过脚本自动标记符合条件的包,无需手动整理编号,效率更高:

  1. 编写Lua脚本:将以下代码保存为gtpv2_cause73_filter.lua
    -- 定义需要的GTPv2字段
    local gtpv2_msg_type = Field.new("gtpv2.msg_type")
    local gtpv2_cause = Field.new("gtpv2.cause")
    local gtpv2_response_to = Field.new("gtpv2.response_to")
    
    -- 创建监听tap
    local target_frames = {}
    local tap = Listener.new("frame", "gtpv2")
    
    function tap.packet(pinfo)
        local msg_type_val = gtpv2_msg_type() and gtpv2_msg_type().value
        local cause_val = gtpv2_cause() and gtpv2_cause().value
        local resp_to_val = gtpv2_response_to() and gtpv2_response_to().value
    
        -- 标记Cause=73的CSResp包
        if msg_type_val == 257 and cause_val == 73 then
            pinfo.marked = true
            if resp_to_val then
                target_frames[tostring(resp_to_val)] = true
            end
        end
    
        -- 标记对应CSReq包
        if msg_type_val == 256 and target_frames[tostring(pinfo.number)] then
            pinfo.marked = true
        end
    end
    
    -- 重置监听状态
    function tap.reset()
        target_frames = {}
    end
    
    -- 启用监听
    tap:enable()
    
  2. 加载脚本到Wireshark:
    • 点击菜单栏「工具 > Lua > 加载Lua脚本」,选择保存的脚本文件
  3. 筛选标记的包:在显示过滤栏输入
    frame.marked == true
    
    即可显示所有符合条件的CSResp及对应CSReq包

方法3:利用GTPv2对话统计

适合快速定位单条对话的场景:

  1. 点击菜单栏「统计 > 对话 > GTPv2」
  2. 在对话列表中,找到包含Cause: 73的会话条目
  3. 右键该条目,选择「过滤对话」,即可显示该会话对应的CSReq和CSResp包

内容的提问来源于stack exchange,提问作者Ders

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 01:53:11