如何使用Wireshark分析CANopen?Ubuntu环境下过滤失效问题求助
Let's walk through the most likely issues and fixes step by step, like we would on a real dev forum:
1. First, Confirm You're Actually Capturing CAN Frames on vcan0
If Wireshark isn't seeing any raw CAN traffic on vcan0, filtering for canopen will naturally return nothing. Here's how to verify and fix this:
- Open a terminal and check if
vcan0is active:
If it doesn't exist, create and enable the virtual CAN interface first:ip link show vcan0sudo modprobe vcan sudo ip link add dev vcan0 type vcan sudo ip link set up vcan0 - In Wireshark, select
vcan0from the interface list and start capturing. Try filtering withcaninstead ofcanopen— if you see raw CAN frames (with IDs, data fields, etc.), your capture setup is working. If not, double-check your vcan interface configuration.
2. Force Wireshark to Decode CAN Frames as CANopen
Older Wireshark versions (like 2.2.6) don't always auto-detect CANopen traffic. You need to manually tell it to parse the frames correctly:
- While capturing, right-click any raw CAN frame in the packet list.
- Hover over Decode As → click Decode As...
- In the dialog box, find the row where the "Current" column shows
can(or the default protocol for your frames). - Click the dropdown in the "Current" column and select
CANopen. - Click OK to save the setting.
Now try filtering with canopen again — you should see parsed CANopen traffic (NMT commands, SDO transfers, PDO messages, etc.).
3. Verify Your CAN Traffic Uses CANopen-Compliant IDs
CANopen relies on specific 11-bit CAN ID ranges for different message types:
- NMT: 0x000
- SDO requests/responses: 0x600-0x6FF
- PDOs: 0x180-0x1FF, 0x200-0x2FF, etc.
If the CAN frames on vcan0 don't fall into these ranges, Wireshark won't recognize them as CANopen, even if you force decoding. Double-check the IDs of the traffic you're capturing.
4. Ensure Wireshark Has Full CANopen Support Installed
On Ubuntu 16.04, make sure you have the complete Wireshark package (not a stripped-down version) installed. Run this in a terminal to verify or reinstall:
sudo apt-get install --reinstall wireshark wireshark-common
This ensures all necessary protocol plugins (including CANopen) are present and properly set up.
内容的提问来源于stack exchange,提问作者Marvin Noll

