<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packeteer/tests/test_snmp.cpp, branch main</title>
<subtitle>Packet capture and analysis, TUI and desktop GUI.
</subtitle>
<id>https://srdusr.com/git/packeteer/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/packeteer/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/'/>
<updated>2025-11-18T20:04:00+00:00</updated>
<entry>
<title>Add SNMP (v1/v2c) with a minimal local ASN.1 BER reader</title>
<updated>2025-11-18T20:04:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-11-18T20:04:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=a8f4866576fd70894ef0080c7797708db664880e'/>
<id>urn:sha1:a8f4866576fd70894ef0080c7797708db664880e</id>
<content type='text'>
First dissector needing actual ASN.1 decoding - a small local
tag/length/value reader, not a general ASN.1 decoder, just enough to
walk SNMP's own SEQUENCE/INTEGER/OCTET STRING structure. v3 wraps the
PDU in its own security-parameters header instead of a plain community
string and can be encrypted, so it's reported by version alone, the
same "don't take on real crypto" call already made for TLS/QUIC.
Community strings are shown as-is, matching FTP's PASS precedent --
v1/v2c send them in the clear regardless.

SnmpDissector takes its port in the constructor so it can be
registered twice, at 161 (agent) and 162 (trap receiver). Unlike
DHCP's 67/68, trap traffic never touches 161 on either side (ephemeral
source port straight to 162), so there's no shared port for
l7_summarize()'s dst-then-src fallback to land on - both ports need
explicit registration.

Live-verified against a real snmpd (net-snmp 5.9.5.2) on loopback: a
real snmpget GetRequest/GetResponse exchange decoded correctly with
matching request-ids across both directions, and a real snmptrap
SNMPv2-Trap on port 162 confirmed the second registered port actually
gets used.
</content>
</entry>
</feed>
