2 * Copyright (c) 1990, 1991, 1993, 1994, 1995, 1996, 1997
3 * The Regents of the University of California. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that: (1) source code distributions
7 * retain the above copyright notice and this paragraph in its entirety, (2)
8 * distributions including binary code include the above copyright notice and
9 * this paragraph in its entirety in the documentation or other materials
10 * provided with the distribution, and (3) all advertising materials mentioning
11 * features or use of this software display the following acknowledgement:
12 * ``This product includes software developed by the University of California,
13 * Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
14 * the University nor the names of its contributors may be used to endorse
15 * or promote products derived from this software without specific prior
17 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
18 * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
21 * Extensively modified by Motonori Shindo (mshindo@mshindo.net) for more
22 * complete PPP support.
29 * o resolve XXX as much as possible
34 #define NETDISSECT_REWORKED
39 #include <tcpdump-stdinc.h>
42 #include <net/slcompress.h>
43 #include <net/if_ppp.h>
48 #include "interface.h"
50 #include "addrtoname.h"
53 #include "ethertype.h"
57 * The following constatns are defined by IANA. Please refer to
58 * http://www.isi.edu/in-notes/iana/assignments/ppp-numbers
59 * for the up-to-date information.
62 /* Protocol Codes defined in ppp.h */
64 static const struct tok ppptype2str[] = {
68 { PPP_DECNET, "DECNET" },
69 { PPP_APPLE, "APPLE" },
71 { PPP_VJC, "VJC IP" },
72 { PPP_VJNC, "VJNC IP" },
73 { PPP_BRPDU, "BRPDU" },
75 { PPP_VINES, "VINES" },
76 { PPP_MPLS_UCAST, "MPLS" },
77 { PPP_MPLS_MCAST, "MPLS" },
78 { PPP_COMP, "Compressed"},
82 { PPP_HELLO, "HELLO" },
83 { PPP_LUXCOM, "LUXCOM" },
86 { PPP_OSICP, "OSICP" },
88 { PPP_DECNETCP, "DECNETCP" },
89 { PPP_APPLECP, "APPLECP" },
90 { PPP_IPXCP, "IPXCP" },
91 { PPP_STIICP, "STIICP" },
92 { PPP_VINESCP, "VINESCP" },
93 { PPP_IPV6CP, "IP6CP" },
94 { PPP_MPLSCP, "MPLSCP" },
101 { PPP_SPAP, "SPAP" },
102 { PPP_SPAP_OLD, "Old-SPAP" },
103 { PPP_BACP, "BACP" },
105 { PPP_MPCP, "MLPPP-CP" },
110 /* Control Protocols (LCP/IPCP/CCP etc.) Codes defined in RFC 1661 */
112 #define CPCODES_VEXT 0 /* Vendor-Specific (RFC2153) */
113 #define CPCODES_CONF_REQ 1 /* Configure-Request */
114 #define CPCODES_CONF_ACK 2 /* Configure-Ack */
115 #define CPCODES_CONF_NAK 3 /* Configure-Nak */
116 #define CPCODES_CONF_REJ 4 /* Configure-Reject */
117 #define CPCODES_TERM_REQ 5 /* Terminate-Request */
118 #define CPCODES_TERM_ACK 6 /* Terminate-Ack */
119 #define CPCODES_CODE_REJ 7 /* Code-Reject */
120 #define CPCODES_PROT_REJ 8 /* Protocol-Reject (LCP only) */
121 #define CPCODES_ECHO_REQ 9 /* Echo-Request (LCP only) */
122 #define CPCODES_ECHO_RPL 10 /* Echo-Reply (LCP only) */
123 #define CPCODES_DISC_REQ 11 /* Discard-Request (LCP only) */
124 #define CPCODES_ID 12 /* Identification (LCP only) RFC1570 */
125 #define CPCODES_TIME_REM 13 /* Time-Remaining (LCP only) RFC1570 */
126 #define CPCODES_RESET_REQ 14 /* Reset-Request (CCP only) RFC1962 */
127 #define CPCODES_RESET_REP 15 /* Reset-Reply (CCP only) */
129 static const struct tok cpcodes[] = {
130 {CPCODES_VEXT, "Vendor-Extension"}, /* RFC2153 */
131 {CPCODES_CONF_REQ, "Conf-Request"},
132 {CPCODES_CONF_ACK, "Conf-Ack"},
133 {CPCODES_CONF_NAK, "Conf-Nack"},
134 {CPCODES_CONF_REJ, "Conf-Reject"},
135 {CPCODES_TERM_REQ, "Term-Request"},
136 {CPCODES_TERM_ACK, "Term-Ack"},
137 {CPCODES_CODE_REJ, "Code-Reject"},
138 {CPCODES_PROT_REJ, "Prot-Reject"},
139 {CPCODES_ECHO_REQ, "Echo-Request"},
140 {CPCODES_ECHO_RPL, "Echo-Reply"},
141 {CPCODES_DISC_REQ, "Disc-Req"},
142 {CPCODES_ID, "Ident"}, /* RFC1570 */
143 {CPCODES_TIME_REM, "Time-Rem"}, /* RFC1570 */
144 {CPCODES_RESET_REQ, "Reset-Req"}, /* RFC1962 */
145 {CPCODES_RESET_REP, "Reset-Ack"}, /* RFC1962 */
149 /* LCP Config Options */
151 #define LCPOPT_VEXT 0
153 #define LCPOPT_ACCM 2
157 #define LCPOPT_DEP6 6
159 #define LCPOPT_ACFC 8
160 #define LCPOPT_FCSALT 9
161 #define LCPOPT_SDP 10
162 #define LCPOPT_NUMMODE 11
163 #define LCPOPT_DEP12 12
164 #define LCPOPT_CBACK 13
165 #define LCPOPT_DEP14 14
166 #define LCPOPT_DEP15 15
167 #define LCPOPT_DEP16 16
168 #define LCPOPT_MLMRRU 17
169 #define LCPOPT_MLSSNHF 18
170 #define LCPOPT_MLED 19
171 #define LCPOPT_PROP 20
172 #define LCPOPT_DCEID 21
173 #define LCPOPT_MPP 22
175 #define LCPOPT_LCPAOPT 24
176 #define LCPOPT_COBS 25
178 #define LCPOPT_MLHF 27
179 #define LCPOPT_I18N 28
180 #define LCPOPT_SDLOS 29
181 #define LCPOPT_PPPMUX 30
183 #define LCPOPT_MIN LCPOPT_VEXT
184 #define LCPOPT_MAX LCPOPT_PPPMUX
186 static const char *lcpconfopts[] = {
187 "Vend-Ext", /* (0) */
190 "Auth-Prot", /* (3) */
191 "Qual-Prot", /* (4) */
192 "Magic-Num", /* (5) */
193 "deprecated(6)", /* used to be a Quality Protocol */
198 "Num-Mode", /* (11) */
199 "deprecated(12)", /* used to be a Multi-Link-Procedure*/
200 "Call-Back", /* (13) */
201 "deprecated(14)", /* used to be a Connect-Time */
202 "deprecated(15)", /* used to be a Compund-Frames */
203 "deprecated(16)", /* used to be a Nominal-Data-Encap */
205 "12-Bit seq #", /* (18) */
206 "End-Disc", /* (19) */
207 "Proprietary", /* (20) */
210 "Link-Disc", /* (23) */
211 "LCP-Auth-Opt", /* (24) */
213 "Prefix-elision", /* (26) */
214 "Multilink-header-Form",/* (27) */
216 "SDL-over-SONET/SDH", /* (29) */
217 "PPP-Muxing", /* (30) */
220 /* ECP - to be supported */
222 /* CCP Config Options */
224 #define CCPOPT_OUI 0 /* RFC1962 */
225 #define CCPOPT_PRED1 1 /* RFC1962 */
226 #define CCPOPT_PRED2 2 /* RFC1962 */
227 #define CCPOPT_PJUMP 3 /* RFC1962 */
228 /* 4-15 unassigned */
229 #define CCPOPT_HPPPC 16 /* RFC1962 */
230 #define CCPOPT_STACLZS 17 /* RFC1974 */
231 #define CCPOPT_MPPC 18 /* RFC2118 */
232 #define CCPOPT_GFZA 19 /* RFC1962 */
233 #define CCPOPT_V42BIS 20 /* RFC1962 */
234 #define CCPOPT_BSDCOMP 21 /* RFC1977 */
236 #define CCPOPT_LZSDCP 23 /* RFC1967 */
237 #define CCPOPT_MVRCA 24 /* RFC1975 */
238 #define CCPOPT_DEC 25 /* RFC1976 */
239 #define CCPOPT_DEFLATE 26 /* RFC1979 */
240 /* 27-254 unassigned */
241 #define CCPOPT_RESV 255 /* RFC1962 */
243 static const struct tok ccpconfopts_values[] = {
244 { CCPOPT_OUI, "OUI" },
245 { CCPOPT_PRED1, "Pred-1" },
246 { CCPOPT_PRED2, "Pred-2" },
247 { CCPOPT_PJUMP, "Puddle" },
248 { CCPOPT_HPPPC, "HP-PPC" },
249 { CCPOPT_STACLZS, "Stac-LZS" },
250 { CCPOPT_MPPC, "MPPC" },
251 { CCPOPT_GFZA, "Gand-FZA" },
252 { CCPOPT_V42BIS, "V.42bis" },
253 { CCPOPT_BSDCOMP, "BSD-Comp" },
254 { CCPOPT_LZSDCP, "LZS-DCP" },
255 { CCPOPT_MVRCA, "MVRCA" },
256 { CCPOPT_DEC, "DEC" },
257 { CCPOPT_DEFLATE, "Deflate" },
258 { CCPOPT_RESV, "Reserved"},
262 /* BACP Config Options */
264 #define BACPOPT_FPEER 1 /* RFC2125 */
266 static const struct tok bacconfopts_values[] = {
267 { BACPOPT_FPEER, "Favored-Peer" },
272 /* SDCP - to be supported */
274 /* IPCP Config Options */
275 #define IPCPOPT_2ADDR 1 /* RFC1172, RFC1332 (deprecated) */
276 #define IPCPOPT_IPCOMP 2 /* RFC1332 */
277 #define IPCPOPT_ADDR 3 /* RFC1332 */
278 #define IPCPOPT_MOBILE4 4 /* RFC2290 */
279 #define IPCPOPT_PRIDNS 129 /* RFC1877 */
280 #define IPCPOPT_PRINBNS 130 /* RFC1877 */
281 #define IPCPOPT_SECDNS 131 /* RFC1877 */
282 #define IPCPOPT_SECNBNS 132 /* RFC1877 */
284 static const struct tok ipcpopt_values[] = {
285 { IPCPOPT_2ADDR, "IP-Addrs" },
286 { IPCPOPT_IPCOMP, "IP-Comp" },
287 { IPCPOPT_ADDR, "IP-Addr" },
288 { IPCPOPT_MOBILE4, "Home-Addr" },
289 { IPCPOPT_PRIDNS, "Pri-DNS" },
290 { IPCPOPT_PRINBNS, "Pri-NBNS" },
291 { IPCPOPT_SECDNS, "Sec-DNS" },
292 { IPCPOPT_SECNBNS, "Sec-NBNS" },
296 #define IPCPOPT_IPCOMP_HDRCOMP 0x61 /* rfc3544 */
297 #define IPCPOPT_IPCOMP_MINLEN 14
299 static const struct tok ipcpopt_compproto_values[] = {
300 { PPP_VJC, "VJ-Comp" },
301 { IPCPOPT_IPCOMP_HDRCOMP, "IP Header Compression" },
305 static const struct tok ipcpopt_compproto_subopt_values[] = {
306 { 1, "RTP-Compression" },
307 { 2, "Enhanced RTP-Compression" },
311 /* IP6CP Config Options */
314 static const struct tok ip6cpopt_values[] = {
315 { IP6CP_IFID, "Interface-ID" },
319 /* ATCP - to be supported */
320 /* OSINLCP - to be supported */
321 /* BVCP - to be supported */
322 /* BCP - to be supported */
323 /* IPXCP - to be supported */
324 /* MPLSCP - to be supported */
326 /* Auth Algorithms */
328 /* 0-4 Reserved (RFC1994) */
329 #define AUTHALG_CHAPMD5 5 /* RFC1994 */
330 #define AUTHALG_MSCHAP1 128 /* RFC2433 */
331 #define AUTHALG_MSCHAP2 129 /* RFC2795 */
333 static const struct tok authalg_values[] = {
334 { AUTHALG_CHAPMD5, "MD5" },
335 { AUTHALG_MSCHAP1, "MS-CHAPv1" },
336 { AUTHALG_MSCHAP2, "MS-CHAPv2" },
340 /* FCS Alternatives - to be supported */
342 /* Multilink Endpoint Discriminator (RFC1717) */
343 #define MEDCLASS_NULL 0 /* Null Class */
344 #define MEDCLASS_LOCAL 1 /* Locally Assigned */
345 #define MEDCLASS_IPV4 2 /* Internet Protocol (IPv4) */
346 #define MEDCLASS_MAC 3 /* IEEE 802.1 global MAC address */
347 #define MEDCLASS_MNB 4 /* PPP Magic Number Block */
348 #define MEDCLASS_PSNDN 5 /* Public Switched Network Director Number */
350 /* PPP LCP Callback */
351 #define CALLBACK_AUTH 0 /* Location determined by user auth */
352 #define CALLBACK_DSTR 1 /* Dialing string */
353 #define CALLBACK_LID 2 /* Location identifier */
354 #define CALLBACK_E164 3 /* E.164 number */
355 #define CALLBACK_X500 4 /* X.500 distinguished name */
356 #define CALLBACK_CBCP 6 /* Location is determined during CBCP nego */
358 static const struct tok ppp_callback_values[] = {
359 { CALLBACK_AUTH, "UserAuth" },
360 { CALLBACK_DSTR, "DialString" },
361 { CALLBACK_LID, "LocalID" },
362 { CALLBACK_E164, "E.164" },
363 { CALLBACK_X500, "X.500" },
364 { CALLBACK_CBCP, "CBCP" },
375 static const struct tok chapcode_values[] = {
376 { CHAP_CHAL, "Challenge" },
377 { CHAP_RESP, "Response" },
378 { CHAP_SUCC, "Success" },
379 { CHAP_FAIL, "Fail" },
389 static const struct tok papcode_values[] = {
390 { PAP_AREQ, "Auth-Req" },
391 { PAP_AACK, "Auth-ACK" },
392 { PAP_ANAK, "Auth-NACK" },
397 #define BAP_CALLREQ 1
398 #define BAP_CALLRES 2
406 static int print_lcp_config_options(netdissect_options *, const u_char *p, int);
407 static int print_ipcp_config_options(netdissect_options *, const u_char *p, int);
408 static int print_ip6cp_config_options(netdissect_options *, const u_char *p, int);
409 static int print_ccp_config_options(netdissect_options *, const u_char *p, int);
410 static int print_bacp_config_options(netdissect_options *, const u_char *p, int);
411 static void handle_ppp(netdissect_options *, u_int proto, const u_char *p, int length);
413 /* generic Control Protocol (e.g. LCP, IPCP, CCP, etc.) handler */
415 handle_ctrl_proto(netdissect_options *ndo,
416 u_int proto, const u_char *pptr, int length)
420 int (*pfunc)(netdissect_options *, const u_char *, int);
426 typestr = tok2str(ppptype2str, "unknown ctrl-proto (0x%04x)", proto);
427 ND_PRINT((ndo, "%s, ", typestr));
429 if (length < 4) /* FIXME weak boundary checking */
431 ND_TCHECK2(*tptr, 2);
435 ND_PRINT((ndo, "%s (0x%02x), id %u, length %u",
436 tok2str(cpcodes, "Unknown Opcode",code),
445 return; /* there may be a NULL confreq etc. */
447 ND_TCHECK2(*tptr, 2);
448 len = EXTRACT_16BITS(tptr);
451 ND_PRINT((ndo, "\n\tencoded length %u (=Option(s) length %u)", len, len - 4));
453 if (ndo->ndo_vflag > 1)
454 print_unknown_data(ndo, pptr - 2, "\n\t", 6);
461 ND_TCHECK2(*tptr, 4);
462 ND_PRINT((ndo, "\n\t Magic-Num 0x%08x", EXTRACT_32BITS(tptr)));
464 ND_TCHECK2(*tptr, 3);
465 ND_PRINT((ndo, " Vendor: %s (%u)",
466 tok2str(oui_values,"Unknown",EXTRACT_24BITS(tptr)),
467 EXTRACT_24BITS(tptr)));
468 /* XXX: need to decode Kind and Value(s)? */
470 case CPCODES_CONF_REQ:
471 case CPCODES_CONF_ACK:
472 case CPCODES_CONF_NAK:
473 case CPCODES_CONF_REJ:
474 x = len - 4; /* Code(1), Identifier(1) and Length(2) */
478 pfunc = print_lcp_config_options;
481 pfunc = print_ipcp_config_options;
484 pfunc = print_ip6cp_config_options;
487 pfunc = print_ccp_config_options;
490 pfunc = print_bacp_config_options;
494 * No print routine for the options for
501 if (pfunc == NULL) /* catch the above null pointer if unknown CP */
504 if ((j = (*pfunc)(ndo, tptr, len)) == 0)
511 case CPCODES_TERM_REQ:
512 case CPCODES_TERM_ACK:
513 /* XXX: need to decode Data? */
515 case CPCODES_CODE_REJ:
516 /* XXX: need to decode Rejected-Packet? */
518 case CPCODES_PROT_REJ:
521 ND_TCHECK2(*tptr, 2);
522 ND_PRINT((ndo, "\n\t Rejected %s Protocol (0x%04x)",
523 tok2str(ppptype2str,"unknown", EXTRACT_16BITS(tptr)),
524 EXTRACT_16BITS(tptr)));
525 /* XXX: need to decode Rejected-Information? - hexdump for now */
527 ND_PRINT((ndo, "\n\t Rejected Packet"));
528 print_unknown_data(ndo, tptr + 2, "\n\t ", len - 2);
531 case CPCODES_ECHO_REQ:
532 case CPCODES_ECHO_RPL:
533 case CPCODES_DISC_REQ:
536 ND_TCHECK2(*tptr, 4);
537 ND_PRINT((ndo, "\n\t Magic-Num 0x%08x", EXTRACT_32BITS(tptr)));
538 /* XXX: need to decode Data? - hexdump for now */
540 ND_PRINT((ndo, "\n\t -----trailing data-----"));
541 ND_TCHECK2(tptr[4], len - 8);
542 print_unknown_data(ndo, tptr + 4, "\n\t ", len - 8);
548 ND_TCHECK2(*tptr, 4);
549 ND_PRINT((ndo, "\n\t Magic-Num 0x%08x", EXTRACT_32BITS(tptr)));
550 /* RFC 1661 says this is intended to be human readable */
552 ND_PRINT((ndo, "\n\t Message\n\t "));
553 if (fn_printn(ndo, tptr + 4, len - 4, ndo->ndo_snapend))
557 case CPCODES_TIME_REM:
560 ND_TCHECK2(*tptr, 4);
561 ND_PRINT((ndo, "\n\t Magic-Num 0x%08x", EXTRACT_32BITS(tptr)));
562 ND_TCHECK2(*(tptr + 4), 4);
563 ND_PRINT((ndo, ", Seconds-Remaining %us", EXTRACT_32BITS(tptr + 4)));
564 /* XXX: need to decode Message? */
567 /* XXX this is dirty but we do not get the
568 * original pointer passed to the begin
570 if (ndo->ndo_vflag <= 1)
571 print_unknown_data(ndo, pptr - 2, "\n\t ", length + 2);
577 ND_PRINT((ndo, "[|%s]", typestr));
580 /* LCP config options */
582 print_lcp_config_options(netdissect_options *ndo,
583 const u_char *p, int length)
595 if ((opt >= LCPOPT_MIN) && (opt <= LCPOPT_MAX))
596 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
597 lcpconfopts[opt], opt, len));
599 ND_PRINT((ndo, "\n\tunknown LCP option 0x%02x", opt));
602 if ((opt >= LCPOPT_MIN) && (opt <= LCPOPT_MAX))
603 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u", lcpconfopts[opt], opt, len));
605 ND_PRINT((ndo, "\n\tunknown LCP option 0x%02x", opt));
612 ND_PRINT((ndo, " (length bogus, should be >= 6)"));
615 ND_TCHECK2(*(p + 2), 3);
616 ND_PRINT((ndo, ": Vendor: %s (%u)",
617 tok2str(oui_values,"Unknown",EXTRACT_24BITS(p+2)),
618 EXTRACT_24BITS(p + 2)));
621 ND_PRINT((ndo, ", kind: 0x%02x", p[5]));
622 ND_PRINT((ndo, ", Value: 0x"));
623 for (i = 0; i < len - 6; i++) {
625 ND_PRINT((ndo, "%02x", p[6 + i]));
631 ND_PRINT((ndo, " (length bogus, should be = 4)"));
634 ND_TCHECK2(*(p + 2), 2);
635 ND_PRINT((ndo, ": %u", EXTRACT_16BITS(p + 2)));
639 ND_PRINT((ndo, " (length bogus, should be = 6)"));
642 ND_TCHECK2(*(p + 2), 4);
643 ND_PRINT((ndo, ": 0x%08x", EXTRACT_32BITS(p + 2)));
647 ND_PRINT((ndo, " (length bogus, should be >= 4)"));
650 ND_TCHECK2(*(p + 2), 2);
651 ND_PRINT((ndo, ": %s", tok2str(ppptype2str, "Unknown Auth Proto (0x04x)", EXTRACT_16BITS(p + 2))));
653 switch (EXTRACT_16BITS(p+2)) {
656 ND_PRINT((ndo, ", %s", tok2str(authalg_values, "Unknown Auth Alg %u", p[4])));
658 case PPP_PAP: /* fall through */
664 print_unknown_data(ndo, p, "\n\t", len);
669 ND_PRINT((ndo, " (length bogus, should be >= 4)"));
672 ND_TCHECK2(*(p + 2), 2);
673 if (EXTRACT_16BITS(p+2) == PPP_LQM)
674 ND_PRINT((ndo, ": LQR"));
676 ND_PRINT((ndo, ": unknown"));
680 ND_PRINT((ndo, " (length bogus, should be = 6)"));
683 ND_TCHECK2(*(p + 2), 4);
684 ND_PRINT((ndo, ": 0x%08x", EXTRACT_32BITS(p + 2)));
692 ND_PRINT((ndo, " (length bogus, should be = 4)"));
695 ND_TCHECK2(*(p + 2), 2);
696 ND_PRINT((ndo, ": 0x%04x", EXTRACT_16BITS(p + 2)));
700 ND_PRINT((ndo, " (length bogus, should be >= 3)"));
703 ND_PRINT((ndo, ": "));
705 ND_PRINT((ndo, ": Callback Operation %s (%u)",
706 tok2str(ppp_callback_values, "Unknown", p[2]),
711 ND_PRINT((ndo, " (length bogus, should be = 4)"));
714 ND_TCHECK2(*(p + 2), 2);
715 ND_PRINT((ndo, ": %u", EXTRACT_16BITS(p + 2)));
719 ND_PRINT((ndo, " (length bogus, should be >= 3)"));
723 switch (p[2]) { /* class */
725 ND_PRINT((ndo, ": Null"));
728 ND_PRINT((ndo, ": Local")); /* XXX */
732 ND_PRINT((ndo, " (length bogus, should be = 7)"));
735 ND_TCHECK2(*(p + 3), 4);
736 ND_PRINT((ndo, ": IPv4 %s", ipaddr_string(ndo, p + 3)));
740 ND_PRINT((ndo, " (length bogus, should be = 9)"));
743 ND_TCHECK2(*(p + 3), 6);
744 ND_PRINT((ndo, ": MAC %s", etheraddr_string(ndo, p + 3)));
747 ND_PRINT((ndo, ": Magic-Num-Block")); /* XXX */
750 ND_PRINT((ndo, ": PSNDN")); /* XXX */
753 ND_PRINT((ndo, ": Unknown class %u", p[2]));
758 /* XXX: to be supported */
783 * Unknown option; dump it as raw bytes now if we're
784 * not going to do so below.
786 if (ndo->ndo_vflag < 2)
787 print_unknown_data(ndo, &p[2], "\n\t ", len - 2);
791 if (ndo->ndo_vflag > 1)
792 print_unknown_data(ndo, &p[2], "\n\t ", len - 2); /* exclude TLV header */
797 ND_PRINT((ndo, "[|lcp]"));
802 static const struct tok ppp_ml_flag_values[] = {
809 handle_mlppp(netdissect_options *ndo,
810 const u_char *p, int length)
813 ND_PRINT((ndo, "MLPPP, "));
815 ND_PRINT((ndo, "seq 0x%03x, Flags [%s], length %u",
816 (EXTRACT_16BITS(p))&0x0fff, /* only support 12-Bit sequence space for now */
817 bittok2str(ppp_ml_flag_values, "none", *p & 0xc0),
823 handle_chap(netdissect_options *ndo,
824 const u_char *p, int length)
827 int val_size, name_size, msg_size;
833 ND_PRINT((ndo, "[|chap]"));
835 } else if (length < 4) {
837 ND_PRINT((ndo, "[|chap 0x%02x]", *p));
843 ND_PRINT((ndo, "CHAP, %s (0x%02x)",
844 tok2str(chapcode_values,"unknown",code),
849 ND_PRINT((ndo, ", id %u", *p)); /* ID */
853 len = EXTRACT_16BITS(p);
857 * Note that this is a generic CHAP decoding routine. Since we
858 * don't know which flavor of CHAP (i.e. CHAP-MD5, MS-CHAPv1,
859 * MS-CHAPv2) is used at this point, we can't decode packet
860 * specifically to each algorithms. Instead, we simply decode
861 * the GCD (Gratest Common Denominator) for all algorithms.
866 if (length - (p - p0) < 1)
869 val_size = *p; /* value size */
871 if (length - (p - p0) < val_size)
873 ND_PRINT((ndo, ", Value "));
874 for (i = 0; i < val_size; i++) {
876 ND_PRINT((ndo, "%02x", *p++));
878 name_size = len - (p - p0);
879 ND_PRINT((ndo, ", Name "));
880 for (i = 0; i < name_size; i++) {
882 safeputchar(ndo, *p++);
887 msg_size = len - (p - p0);
888 ND_PRINT((ndo, ", Msg "));
889 for (i = 0; i< msg_size; i++) {
891 safeputchar(ndo, *p++);
898 ND_PRINT((ndo, "[|chap]"));
901 /* PAP (see RFC 1334) */
903 handle_pap(netdissect_options *ndo,
904 const u_char *p, int length)
907 int peerid_len, passwd_len, msg_len;
913 ND_PRINT((ndo, "[|pap]"));
915 } else if (length < 4) {
917 ND_PRINT((ndo, "[|pap 0x%02x]", *p));
923 ND_PRINT((ndo, "PAP, %s (0x%02x)",
924 tok2str(papcode_values, "unknown", code),
929 ND_PRINT((ndo, ", id %u", *p)); /* ID */
933 len = EXTRACT_16BITS(p);
936 if ((int)len > length) {
937 ND_PRINT((ndo, ", length %u > packet size", len));
941 if (length < (p - p0)) {
942 ND_PRINT((ndo, ", length %u < PAP header length", length));
948 if (length - (p - p0) < 1)
951 peerid_len = *p; /* Peer-ID Length */
953 if (length - (p - p0) < peerid_len)
955 ND_PRINT((ndo, ", Peer "));
956 for (i = 0; i < peerid_len; i++) {
958 safeputchar(ndo, *p++);
961 if (length - (p - p0) < 1)
964 passwd_len = *p; /* Password Length */
966 if (length - (p - p0) < passwd_len)
968 ND_PRINT((ndo, ", Name "));
969 for (i = 0; i < passwd_len; i++) {
971 safeputchar(ndo, *p++);
976 if (length - (p - p0) < 1)
979 msg_len = *p; /* Msg-Length */
981 if (length - (p - p0) < msg_len)
983 ND_PRINT((ndo, ", Msg "));
984 for (i = 0; i< msg_len; i++) {
986 safeputchar(ndo, *p++);
993 ND_PRINT((ndo, "[|pap]"));
998 handle_bap(netdissect_options *ndo _U_,
999 const u_char *p _U_, int length _U_)
1001 /* XXX: to be supported!! */
1005 /* IPCP config options */
1007 print_ipcp_config_options(netdissect_options *ndo,
1008 const u_char *p, int length)
1011 u_int compproto, ipcomp_subopttotallen, ipcomp_subopt, ipcomp_suboptlen;
1021 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1022 tok2str(ipcpopt_values,"unknown",opt),
1028 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u",
1029 tok2str(ipcpopt_values,"unknown",opt),
1034 case IPCPOPT_2ADDR: /* deprecated */
1036 ND_PRINT((ndo, " (length bogus, should be = 10)"));
1039 ND_TCHECK2(*(p + 6), 4);
1040 ND_PRINT((ndo, ": src %s, dst %s",
1041 ipaddr_string(ndo, p + 2),
1042 ipaddr_string(ndo, p + 6)));
1044 case IPCPOPT_IPCOMP:
1046 ND_PRINT((ndo, " (length bogus, should be >= 4)"));
1049 ND_TCHECK2(*(p + 2), 2);
1050 compproto = EXTRACT_16BITS(p+2);
1052 ND_PRINT((ndo, ": %s (0x%02x):",
1053 tok2str(ipcpopt_compproto_values, "Unknown", compproto),
1056 switch (compproto) {
1058 /* XXX: VJ-Comp parameters should be decoded */
1060 case IPCPOPT_IPCOMP_HDRCOMP:
1061 if (len < IPCPOPT_IPCOMP_MINLEN) {
1062 ND_PRINT((ndo, " (length bogus, should be >= %u)",
1063 IPCPOPT_IPCOMP_MINLEN));
1067 ND_TCHECK2(*(p + 2), IPCPOPT_IPCOMP_MINLEN);
1068 ND_PRINT((ndo, "\n\t TCP Space %u, non-TCP Space %u" \
1069 ", maxPeriod %u, maxTime %u, maxHdr %u",
1070 EXTRACT_16BITS(p+4),
1071 EXTRACT_16BITS(p+6),
1072 EXTRACT_16BITS(p+8),
1073 EXTRACT_16BITS(p+10),
1074 EXTRACT_16BITS(p+12)));
1076 /* suboptions present ? */
1077 if (len > IPCPOPT_IPCOMP_MINLEN) {
1078 ipcomp_subopttotallen = len - IPCPOPT_IPCOMP_MINLEN;
1079 p += IPCPOPT_IPCOMP_MINLEN;
1081 ND_PRINT((ndo, "\n\t Suboptions, length %u", ipcomp_subopttotallen));
1083 while (ipcomp_subopttotallen >= 2) {
1086 ipcomp_suboptlen = *(p+1);
1089 if (ipcomp_subopt == 0 ||
1090 ipcomp_suboptlen == 0 )
1093 /* XXX: just display the suboptions for now */
1094 ND_PRINT((ndo, "\n\t\t%s Suboption #%u, length %u",
1095 tok2str(ipcpopt_compproto_subopt_values,
1101 ipcomp_subopttotallen -= ipcomp_suboptlen;
1102 p += ipcomp_suboptlen;
1111 case IPCPOPT_ADDR: /* those options share the same format - fall through */
1112 case IPCPOPT_MOBILE4:
1113 case IPCPOPT_PRIDNS:
1114 case IPCPOPT_PRINBNS:
1115 case IPCPOPT_SECDNS:
1116 case IPCPOPT_SECNBNS:
1118 ND_PRINT((ndo, " (length bogus, should be = 6)"));
1121 ND_TCHECK2(*(p + 2), 4);
1122 ND_PRINT((ndo, ": %s", ipaddr_string(ndo, p + 2)));
1126 * Unknown option; dump it as raw bytes now if we're
1127 * not going to do so below.
1129 if (ndo->ndo_vflag < 2)
1130 print_unknown_data(ndo, &p[2], "\n\t ", len - 2);
1133 if (ndo->ndo_vflag > 1)
1134 print_unknown_data(ndo, &p[2], "\n\t ", len - 2); /* exclude TLV header */
1138 ND_PRINT((ndo, "[|ipcp]"));
1142 /* IP6CP config options */
1144 print_ip6cp_config_options(netdissect_options *ndo,
1145 const u_char *p, int length)
1157 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1158 tok2str(ip6cpopt_values,"unknown",opt),
1164 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u",
1165 tok2str(ip6cpopt_values,"unknown",opt),
1172 ND_PRINT((ndo, " (length bogus, should be = 10)"));
1175 ND_TCHECK2(*(p + 2), 8);
1176 ND_PRINT((ndo, ": %04x:%04x:%04x:%04x",
1177 EXTRACT_16BITS(p + 2),
1178 EXTRACT_16BITS(p + 4),
1179 EXTRACT_16BITS(p + 6),
1180 EXTRACT_16BITS(p + 8)));
1184 * Unknown option; dump it as raw bytes now if we're
1185 * not going to do so below.
1187 if (ndo->ndo_vflag < 2)
1188 print_unknown_data(ndo, &p[2], "\n\t ", len - 2);
1191 if (ndo->ndo_vflag > 1)
1192 print_unknown_data(ndo, &p[2], "\n\t ", len - 2); /* exclude TLV header */
1197 ND_PRINT((ndo, "[|ip6cp]"));
1202 /* CCP config options */
1204 print_ccp_config_options(netdissect_options *ndo,
1205 const u_char *p, int length)
1217 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1218 tok2str(ccpconfopts_values, "Unknown", opt),
1224 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u",
1225 tok2str(ccpconfopts_values, "Unknown", opt),
1230 case CCPOPT_BSDCOMP:
1232 ND_PRINT((ndo, " (length bogus, should be >= 3)"));
1235 ND_TCHECK2(*(p + 2), 1);
1236 ND_PRINT((ndo, ": Version: %u, Dictionary Bits: %u",
1237 p[2] >> 5, p[2] & 0x1f));
1241 ND_PRINT((ndo, " (length bogus, should be >= 4)"));
1244 ND_TCHECK2(*(p + 2), 1);
1245 ND_PRINT((ndo, ": Features: %u, PxP: %s, History: %u, #CTX-ID: %u",
1247 (p[2] & 0x20) ? "Enabled" : "Disabled",
1248 p[2] & 0x1f, p[3]));
1250 case CCPOPT_DEFLATE:
1252 ND_PRINT((ndo, " (length bogus, should be >= 4)"));
1255 ND_TCHECK2(*(p + 2), 1);
1256 ND_PRINT((ndo, ": Window: %uK, Method: %s (0x%x), MBZ: %u, CHK: %u",
1258 ((p[2] & 0x0f) == 8) ? "zlib" : "unkown",
1259 p[2] & 0x0f, (p[3] & 0xfc) >> 2, p[3] & 0x03));
1262 /* XXX: to be supported */
1269 case CCPOPT_STACLZS:
1280 * Unknown option; dump it as raw bytes now if we're
1281 * not going to do so below.
1283 if (ndo->ndo_vflag < 2)
1284 print_unknown_data(ndo, &p[2], "\n\t ", len - 2);
1287 if (ndo->ndo_vflag > 1)
1288 print_unknown_data(ndo, &p[2], "\n\t ", len - 2); /* exclude TLV header */
1293 ND_PRINT((ndo, "[|ccp]"));
1297 /* BACP config options */
1299 print_bacp_config_options(netdissect_options *ndo,
1300 const u_char *p, int length)
1312 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1313 tok2str(bacconfopts_values, "Unknown", opt),
1319 ND_PRINT((ndo, "\n\t %s Option (0x%02x), length %u",
1320 tok2str(bacconfopts_values, "Unknown", opt),
1327 ND_PRINT((ndo, " (length bogus, should be = 6)"));
1330 ND_TCHECK2(*(p + 2), 4);
1331 ND_PRINT((ndo, ": Magic-Num 0x%08x", EXTRACT_32BITS(p + 2)));
1335 * Unknown option; dump it as raw bytes now if we're
1336 * not going to do so below.
1338 if (ndo->ndo_vflag < 2)
1339 print_unknown_data(ndo, &p[2], "\n\t ", len - 2);
1342 if (ndo->ndo_vflag > 1)
1343 print_unknown_data(ndo, &p[2], "\n\t ", len - 2); /* exclude TLV header */
1348 ND_PRINT((ndo, "[|bacp]"));
1353 ppp_hdlc(netdissect_options *ndo,
1354 const u_char *p, int length)
1364 b = (u_char *)malloc(length);
1369 * Unescape all the data into a temporary, private, buffer.
1370 * Do this so that we dont overwrite the original packet
1373 for (s = p, t = b, i = length; i > 0 && ND_TTEST(*s); i--) {
1376 if (i <= 1 || !ND_TTEST(*s))
1384 se = ndo->ndo_snapend;
1385 ndo->ndo_snapend = t;
1388 /* now lets guess about the payload codepoint format */
1391 proto = *b; /* start with a one-octet codepoint guess */
1395 ip_print(ndo, b + 1, length - 1);
1398 ip6_print(ndo, b + 1, length - 1);
1400 default: /* no luck - try next guess */
1406 proto = EXTRACT_16BITS(b); /* next guess - load two octets */
1409 case (PPP_ADDRESS << 8 | PPP_CONTROL): /* looks like a PPP frame */
1412 proto = EXTRACT_16BITS(b+2); /* load the PPP proto-id */
1413 handle_ppp(ndo, proto, b + 4, length - 4);
1415 default: /* last guess - proto must be a PPP proto-id */
1416 handle_ppp(ndo, proto, b + 2, length - 2);
1421 ndo->ndo_snapend = se;
1426 ndo->ndo_snapend = se;
1428 ND_PRINT((ndo, "[|ppp]"));
1434 handle_ppp(netdissect_options *ndo,
1435 u_int proto, const u_char *p, int length)
1437 if ((proto & 0xff00) == 0x7e00) { /* is this an escape code ? */
1438 ppp_hdlc(ndo, p - 1, length);
1443 case PPP_LCP: /* fall through */
1450 handle_ctrl_proto(ndo, proto, p, length);
1453 handle_mlppp(ndo, p, length);
1456 handle_chap(ndo, p, length);
1459 handle_pap(ndo, p, length);
1461 case PPP_BAP: /* XXX: not yet completed */
1462 handle_bap(ndo, p, length);
1464 case ETHERTYPE_IP: /*XXX*/
1467 ip_print(ndo, p, length);
1469 case ETHERTYPE_IPV6: /*XXX*/
1471 ip6_print(ndo, p, length);
1473 case ETHERTYPE_IPX: /*XXX*/
1475 ipx_print(ndo, p, length);
1478 isoclns_print(ndo, p, length, length);
1480 case PPP_MPLS_UCAST:
1481 case PPP_MPLS_MCAST:
1482 mpls_print(ndo, p, length);
1485 ND_PRINT((ndo, "compressed PPP data"));
1488 ND_PRINT((ndo, "%s ", tok2str(ppptype2str, "unknown PPP protocol (0x%04x)", proto)));
1489 print_unknown_data(ndo, p, "\n\t", length);
1494 /* Standard PPP printer */
1496 ppp_print(netdissect_options *ndo,
1497 register const u_char *p, u_int length)
1499 u_int proto,ppp_header;
1500 u_int olen = length; /* _o_riginal length */
1504 * Here, we assume that p points to the Address and Control
1505 * field (if they present).
1510 ppp_header = EXTRACT_16BITS(p);
1512 switch(ppp_header) {
1513 case (PPP_WITHDIRECTION_IN << 8 | PPP_CONTROL):
1514 if (ndo->ndo_eflag) ND_PRINT((ndo, "In "));
1519 case (PPP_WITHDIRECTION_OUT << 8 | PPP_CONTROL):
1520 if (ndo->ndo_eflag) ND_PRINT((ndo, "Out "));
1525 case (PPP_ADDRESS << 8 | PPP_CONTROL):
1526 p += 2; /* ACFC not used */
1539 proto = *p; /* PFC is used */
1545 proto = EXTRACT_16BITS(p);
1552 ND_PRINT((ndo, "%s (0x%04x), length %u: ",
1553 tok2str(ppptype2str, "unknown", proto),
1557 handle_ppp(ndo, proto, p, length);
1560 ND_PRINT((ndo, "[|ppp]"));
1565 /* PPP I/F printer */
1567 ppp_if_print(netdissect_options *ndo,
1568 const struct pcap_pkthdr *h, register const u_char *p)
1570 register u_int length = h->len;
1571 register u_int caplen = h->caplen;
1573 if (caplen < PPP_HDRLEN) {
1574 ND_PRINT((ndo, "[|ppp]"));
1580 * XXX: seems to assume that there are 2 octets prepended to an
1581 * actual PPP frame. The 1st octet looks like Input/Output flag
1582 * while 2nd octet is unknown, at least to me
1583 * (mshindo@mshindo.net).
1585 * That was what the original tcpdump code did.
1587 * FreeBSD's "if_ppp.c" *does* set the first octet to 1 for outbound
1588 * packets and 0 for inbound packets - but only if the
1589 * protocol field has the 0x8000 bit set (i.e., it's a network
1590 * control protocol); it does so before running the packet through
1591 * "bpf_filter" to see if it should be discarded, and to see
1592 * if we should update the time we sent the most recent packet...
1594 * ...but it puts the original address field back after doing
1597 * NetBSD's "if_ppp.c" doesn't set the first octet in that fashion.
1599 * I don't know if any PPP implementation handed up to a BPF
1600 * device packets with the first octet being 1 for outbound and
1601 * 0 for inbound packets, so I (guy@alum.mit.edu) don't know
1602 * whether that ever needs to be checked or not.
1604 * Note that NetBSD has a DLT_PPP_SERIAL, which it uses for PPP,
1605 * and its tcpdump appears to assume that the frame always
1606 * begins with an address field and a control field, and that
1607 * the address field might be 0x0f or 0x8f, for Cisco
1608 * point-to-point with HDLC framing as per section 4.3.1 of RFC
1609 * 1547, as well as 0xff, for PPP in HDLC-like framing as per
1612 * (Is the Cisco framing in question what DLT_C_HDLC, in
1616 ND_PRINT((ndo, "%c %4d %02x ", p[0] ? 'O' : 'I', length, p[1]));
1619 ppp_print(ndo, p, length);
1625 * PPP I/F printer to use if we know that RFC 1662-style PPP in HDLC-like
1626 * framing, or Cisco PPP with HDLC framing as per section 4.3.1 of RFC 1547,
1627 * is being used (i.e., we don't check for PPP_ADDRESS and PPP_CONTROL,
1628 * discard them *if* those are the first two octets, and parse the remaining
1629 * packet as a PPP packet, as "ppp_print()" does).
1631 * This handles, for example, DLT_PPP_SERIAL in NetBSD.
1634 ppp_hdlc_if_print(netdissect_options *ndo,
1635 const struct pcap_pkthdr *h, register const u_char *p)
1637 register u_int length = h->len;
1638 register u_int caplen = h->caplen;
1643 ND_PRINT((ndo, "[|ppp]"));
1651 ND_PRINT((ndo, "[|ppp]"));
1656 ND_PRINT((ndo, "%02x %02x %d ", p[0], p[1], length));
1661 proto = EXTRACT_16BITS(p);
1665 ND_PRINT((ndo, "%s: ", tok2str(ppptype2str, "unknown PPP protocol (0x%04x)", proto)));
1667 handle_ppp(ndo, proto, p, length);
1672 return (chdlc_if_print(ndo, h, p));
1676 ND_PRINT((ndo, "%02x %02x %d ", p[0], p[1], length));
1681 * XXX - NetBSD's "ppp_netbsd_serial_if_print()" treats
1682 * the next two octets as an Ethernet type; does that
1685 ND_PRINT((ndo, "unknown addr %02x; ctrl %02x", p[0], p[1]));
1692 #define PPP_BSDI_HDRLEN 24
1694 /* BSD/OS specific PPP printer */
1696 ppp_bsdos_if_print(netdissect_options *ndo _U_,
1697 const struct pcap_pkthdr *h _U_, register const u_char *p _U_)
1699 register int hdrlength;
1701 register u_int length = h->len;
1702 register u_int caplen = h->caplen;
1707 if (caplen < PPP_BSDI_HDRLEN) {
1708 ND_PRINT((ndo, "[|ppp]"));
1715 if (p[0] == PPP_ADDRESS && p[1] == PPP_CONTROL) {
1717 ND_PRINT((ndo, "%02x %02x ", p[0], p[1]));
1723 ND_PRINT((ndo, "%d ", length));
1724 /* Retrieve the protocol type */
1726 /* Compressed protocol field */
1729 ND_PRINT((ndo, "%02x ", ptype));
1733 /* Un-compressed protocol field */
1734 ptype = EXTRACT_16BITS(p);
1736 ND_PRINT((ndo, "%04x ", ptype));
1743 ND_PRINT((ndo, "%c ", p[SLC_DIR] ? 'O' : 'I'));
1745 /* link level header */
1746 struct ppp_header *ph;
1748 q = p + SLC_BPFHDRLEN;
1749 ph = (struct ppp_header *)q;
1750 if (ph->phdr_addr == PPP_ADDRESS
1751 && ph->phdr_ctl == PPP_CONTROL) {
1753 ND_PRINT((ndo, "%02x %02x ", q[0], q[1]));
1754 ptype = EXTRACT_16BITS(&ph->phdr_type);
1755 if (ndo->ndo_eflag && (ptype == PPP_VJC || ptype == PPP_VJNC)) {
1756 ND_PRINT((ndo, "%s ", tok2str(ppptype2str,
1757 "proto-#%d", ptype)));
1760 if (ndo->ndo_eflag) {
1761 ND_PRINT((ndo, "LLH=["));
1762 for (i = 0; i < p[SLC_LLHL]; i++)
1763 ND_PRINT((ndo, "%02x", q[i]));
1764 ND_PRINT((ndo, "] "));
1769 ND_PRINT((ndo, "%d ", length));
1771 q = p + SLC_BPFHDRLEN + p[SLC_LLHL];
1775 ptype = vjc_print(ndo, q, ptype);
1776 hdrlength = PPP_BSDI_HDRLEN;
1780 ip_print(ndo, p, length);
1783 ip6_print(ndo, p, length);
1785 case PPP_MPLS_UCAST:
1786 case PPP_MPLS_MCAST:
1787 mpls_print(ndo, p, length);
1792 ptype = vjc_print(ndo, q, ptype);
1793 hdrlength = PPP_BSDI_HDRLEN;
1797 ip_print(ndo, p, length);
1800 ip6_print(ndo, p, length);
1802 case PPP_MPLS_UCAST:
1803 case PPP_MPLS_MCAST:
1804 mpls_print(ndo, p, length);
1809 if (ndo->ndo_eflag) {
1810 ND_PRINT((ndo, "CH=["));
1811 for (i = 0; i < p[SLC_LLHL]; i++)
1812 ND_PRINT((ndo, "%02x", q[i]));
1813 ND_PRINT((ndo, "] "));
1819 hdrlength = PPP_BSDI_HDRLEN;
1822 length -= hdrlength;
1827 ip_print(p, length);
1830 ip6_print(ndo, p, length);
1832 case PPP_MPLS_UCAST:
1833 case PPP_MPLS_MCAST:
1834 mpls_print(ndo, p, length);
1837 ND_PRINT((ndo, "%s ", tok2str(ppptype2str, "unknown PPP protocol (0x%04x)", ptype)));
1843 #endif /* __bsdi__ */
1850 * c-style: whitesmith