Wiresharking IEC
Jump to navigation
Jump to search
Some basic filters for analysing wireshark logs in case of IEC protocols
IEC60870-5-104
Filter information object address 401
104asdu.ioa == 401
Dispaly packages with TCP length>0 (no ack messages)
tcp.len>0
Inrogen: GI
Spont: Spontaneous event
IOA: Information Object Address
Act: activation message (select/execute)
ActCon: activation confirmation
ActTerm: activation termination