2 * Copyright (c) 1998-2007 The TCPDUMP project
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that: (1) source code
6 * distributions retain the above copyright notice and this paragraph
7 * in its entirety, and (2) distributions including binary code include
8 * the above copyright notice and this paragraph in its entirety in
9 * the documentation or other materials provided with the distribution.
10 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND
11 * WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT
12 * LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
13 * FOR A PARTICULAR PURPOSE.
15 * Support for the Light Weight Access Point Protocol as per draft-ohara-capwap-lwapp-04
17 * Original code by Carles Kishimoto <carles.kishimoto@gmail.com>
24 #include <tcpdump-stdinc.h>
30 #include "interface.h"
32 #include "addrtoname.h"
35 * LWAPP transport (common) header
37 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
38 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
39 * |VER| RID |C|F|L| Frag ID | Length |
40 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
41 * | Status/WLANs | Payload... |
42 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
46 struct lwapp_transport_header
{
54 * LWAPP control header
56 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
57 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
58 * | Message Type | Seq Num | Msg Element Length |
59 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
61 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
62 * | Msg Element [0..N] |
63 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
66 struct lwapp_control_header
{
70 u_int8_t session_id
[4];
73 #define LWAPP_VERSION 0
74 #define LWAPP_EXTRACT_VERSION(x) (((x)&0xC0)>>6)
75 #define LWAPP_EXTRACT_RID(x) (((x)&0x38)>>3)
76 #define LWAPP_EXTRACT_CONTROL_BIT(x) (((x)&0x04)>>2)
78 static const struct tok lwapp_header_bits_values
[] = {
79 { 0x01, "Last Fragment Bit"},
80 { 0x02, "Fragment Bit"},
81 { 0x04, "Control Bit"},
85 #define LWAPP_MSGTYPE_DISCOVERY_REQUEST 1
86 #define LWAPP_MSGTYPE_DISCOVERY_RESPONSE 2
87 #define LWAPP_MSGTYPE_JOIN_REQUEST 3
88 #define LWAPP_MSGTYPE_JOIN_RESPONSE 4
89 #define LWAPP_MSGTYPE_JOIN_ACK 5
90 #define LWAPP_MSGTYPE_JOIN_CONFIRM 6
91 #define LWAPP_MSGTYPE_CONFIGURE_REQUEST 10
92 #define LWAPP_MSGTYPE_CONFIGURE_RESPONSE 11
93 #define LWAPP_MSGTYPE_CONF_UPDATE_REQUEST 12
94 #define LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE 13
95 #define LWAPP_MSGTYPE_WTP_EVENT_REQUEST 14
96 #define LWAPP_MSGTYPE_WTP_EVENT_RESPONSE 15
97 #define LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST 16
98 #define LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE 17
99 #define LWAPP_MSGTYPE_ECHO_REQUEST 22
100 #define LWAPP_MSGTYPE_ECHO_RESPONSE 23
101 #define LWAPP_MSGTYPE_IMAGE_DATA_REQUEST 24
102 #define LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE 25
103 #define LWAPP_MSGTYPE_RESET_REQUEST 26
104 #define LWAPP_MSGTYPE_RESET_RESPONSE 27
105 #define LWAPP_MSGTYPE_KEY_UPDATE_REQUEST 30
106 #define LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE 31
107 #define LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST 32
108 #define LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE 33
109 #define LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST 34
110 #define LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE 35
111 #define LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION 36
112 #define LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST 37
113 #define LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE 38
114 #define LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST 39
115 #define LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE 40
117 static const struct tok lwapp_msg_type_values
[] = {
118 { LWAPP_MSGTYPE_DISCOVERY_REQUEST
, "Discovery req"},
119 { LWAPP_MSGTYPE_DISCOVERY_RESPONSE
, "Discovery resp"},
120 { LWAPP_MSGTYPE_JOIN_REQUEST
, "Join req"},
121 { LWAPP_MSGTYPE_JOIN_RESPONSE
, "Join resp"},
122 { LWAPP_MSGTYPE_JOIN_ACK
, "Join ack"},
123 { LWAPP_MSGTYPE_JOIN_CONFIRM
, "Join confirm"},
124 { LWAPP_MSGTYPE_CONFIGURE_REQUEST
, "Configure req"},
125 { LWAPP_MSGTYPE_CONFIGURE_RESPONSE
, "Configure resp"},
126 { LWAPP_MSGTYPE_CONF_UPDATE_REQUEST
, "Update req"},
127 { LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE
, "Update resp"},
128 { LWAPP_MSGTYPE_WTP_EVENT_REQUEST
, "WTP event req"},
129 { LWAPP_MSGTYPE_WTP_EVENT_RESPONSE
, "WTP event resp"},
130 { LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST
, "Change state event req"},
131 { LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE
, "Change state event resp"},
132 { LWAPP_MSGTYPE_ECHO_REQUEST
, "Echo req"},
133 { LWAPP_MSGTYPE_ECHO_RESPONSE
, "Echo resp"},
134 { LWAPP_MSGTYPE_IMAGE_DATA_REQUEST
, "Image data req"},
135 { LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE
, "Image data resp"},
136 { LWAPP_MSGTYPE_RESET_REQUEST
, "Channel status req"},
137 { LWAPP_MSGTYPE_RESET_RESPONSE
, "Channel status resp"},
138 { LWAPP_MSGTYPE_KEY_UPDATE_REQUEST
, "Key update req"},
139 { LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE
, "Key update resp"},
140 { LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST
, "Primary discovery req"},
141 { LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE
, "Primary discovery resp"},
142 { LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST
, "Data transfer req"},
143 { LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE
, "Data transfer resp"},
144 { LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION
, "Clear config ind"},
145 { LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST
, "Wlan config req"},
146 { LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE
, "Wlan config resp"},
147 { LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST
, "Mobile config req"},
148 { LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE
, "Mobile config resp"},
153 * LWAPP message elements
156 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
157 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
158 * | Type | Length | Value ... |
159 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
161 struct lwapp_message_header
{
167 lwapp_control_print(const u_char
*pptr
, u_int len
, int has_ap_ident
) {
169 const struct lwapp_transport_header
*lwapp_trans_header
;
170 const struct lwapp_control_header
*lwapp_control_header
;
178 /* check if enough bytes for AP identity */
179 if (!TTEST2(*tptr
, 6))
181 lwapp_trans_header
= (const struct lwapp_transport_header
*)(pptr
+6);
183 lwapp_trans_header
= (const struct lwapp_transport_header
*)pptr
;
185 TCHECK(*lwapp_trans_header
);
188 * Sanity checking of the header.
190 if (LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
) != LWAPP_VERSION
) {
191 printf("LWAPP version %u packet not supported",
192 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
));
198 printf("LWAPPv%u, %s frame, Flags [%s], length %u",
199 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
200 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
201 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
206 /* ok they seem to want to know everything - lets fully decode it */
207 tlen
=EXTRACT_16BITS(lwapp_trans_header
->length
);
209 printf("LWAPPv%u, %s frame, Radio-id %u, Flags [%s], Frag-id %u, length %u",
210 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
211 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
212 LWAPP_EXTRACT_RID(lwapp_trans_header
->version
),
213 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
214 lwapp_trans_header
->frag_id
,
218 printf("\n\tAP identity: %s",
219 etheraddr_string(tptr
));
220 tptr
+=sizeof(const struct lwapp_transport_header
)+6;
222 tptr
+=sizeof(const struct lwapp_transport_header
);
227 /* did we capture enough for fully decoding the object header ? */
228 if (!TTEST2(*tptr
, sizeof(struct lwapp_control_header
)))
231 lwapp_control_header
= (const struct lwapp_control_header
*)tptr
;
232 msg_tlen
= EXTRACT_16BITS(lwapp_control_header
->len
);
234 /* print message header */
235 printf("\n\t Msg type: %s (%u), Seqnum: %u, Msg len: %d, Session: 0x%08x",
236 tok2str(lwapp_msg_type_values
,"Unknown",lwapp_control_header
->msg_type
),
237 lwapp_control_header
->msg_type
,
238 lwapp_control_header
->seq_num
,
240 EXTRACT_32BITS(lwapp_control_header
->session_id
));
242 /* did we capture enough for fully decoding the message */
243 if (!TTEST2(*tptr
, msg_tlen
))
246 /* XXX - Decode sub messages for each message */
247 switch(lwapp_control_header
->msg_type
) {
248 case LWAPP_MSGTYPE_DISCOVERY_REQUEST
:
249 case LWAPP_MSGTYPE_DISCOVERY_RESPONSE
:
250 case LWAPP_MSGTYPE_JOIN_REQUEST
:
251 case LWAPP_MSGTYPE_JOIN_RESPONSE
:
252 case LWAPP_MSGTYPE_JOIN_ACK
:
253 case LWAPP_MSGTYPE_JOIN_CONFIRM
:
254 case LWAPP_MSGTYPE_CONFIGURE_REQUEST
:
255 case LWAPP_MSGTYPE_CONFIGURE_RESPONSE
:
256 case LWAPP_MSGTYPE_CONF_UPDATE_REQUEST
:
257 case LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE
:
258 case LWAPP_MSGTYPE_WTP_EVENT_REQUEST
:
259 case LWAPP_MSGTYPE_WTP_EVENT_RESPONSE
:
260 case LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST
:
261 case LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE
:
262 case LWAPP_MSGTYPE_ECHO_REQUEST
:
263 case LWAPP_MSGTYPE_ECHO_RESPONSE
:
264 case LWAPP_MSGTYPE_IMAGE_DATA_REQUEST
:
265 case LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE
:
266 case LWAPP_MSGTYPE_RESET_REQUEST
:
267 case LWAPP_MSGTYPE_RESET_RESPONSE
:
268 case LWAPP_MSGTYPE_KEY_UPDATE_REQUEST
:
269 case LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE
:
270 case LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST
:
271 case LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE
:
272 case LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST
:
273 case LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE
:
274 case LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION
:
275 case LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST
:
276 case LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE
:
277 case LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST
:
278 case LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE
:
283 tptr
+= sizeof(struct lwapp_control_header
) + msg_tlen
;
284 tlen
-= sizeof(struct lwapp_control_header
) + msg_tlen
;
289 printf("\n\t\t packet exceeded snapshot");
293 lwapp_data_print(const u_char
*pptr
, u_int len
) {
295 const struct lwapp_transport_header
*lwapp_trans_header
;
301 /* check if enough bytes for AP identity */
302 if (!TTEST2(*tptr
, 6))
304 lwapp_trans_header
= (const struct lwapp_transport_header
*)pptr
;
305 TCHECK(*lwapp_trans_header
);
308 * Sanity checking of the header.
310 if (LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
) != LWAPP_VERSION
) {
311 printf("LWAPP version %u packet not supported",
312 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
));
318 printf("LWAPPv%u, %s frame, Flags [%s], length %u",
319 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
320 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
321 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
326 /* ok they seem to want to know everything - lets fully decode it */
327 tlen
=EXTRACT_16BITS(lwapp_trans_header
->length
);
329 printf("LWAPPv%u, %s frame, Radio-id %u, Flags [%s], Frag-id %u, length %u",
330 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
331 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
332 LWAPP_EXTRACT_RID(lwapp_trans_header
->version
),
333 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
334 lwapp_trans_header
->frag_id
,
337 tptr
+=sizeof(const struct lwapp_transport_header
);
338 tlen
-=sizeof(const struct lwapp_transport_header
);
340 /* FIX - An IEEE 802.11 frame follows - hexdump for now */
341 print_unknown_data(gndo
,tptr
, "\n\t", tlen
);
346 printf("\n\t\t packet exceeded snapshot");
351 * c-style: whitesmith