Display Filter Reference: Encapsulating Security Payload

Protocol field name: esp

Versions: 1.0.0 to 2.4.4

Back to Display Filter Reference

Field name Description Type Versions
esp.authentication_data Authentication Data Sequence of bytes 2.0.0 to 2.4.4
esp.icv_bad Bad Boolean 1.10.0 to 2.4.4
esp.icv_good Good Boolean 1.10.0 to 2.4.4
esp.iv ESP IV Sequence of bytes 1.0.0 to 2.4.4
esp.pad Pad Sequence of bytes 2.0.0 to 2.4.4
esp.pad_len ESP Pad Length Unsigned integer, 1 byte 1.0.0 to 2.4.4
esp.protocol ESP Next Header Unsigned integer, 1 byte 1.0.0 to 2.4.4
esp.sequence ESP Sequence Unsigned integer, 4 bytes 1.0.0 to 2.4.4
esp.sequence-analysis.expected-sn Expected SN Unsigned integer, 4 bytes 2.0.0 to 2.4.4
esp.sequence-analysis.previous-frame Previous Frame Frame number 2.0.0 to 2.4.4
esp.sequence-analysis.wrong-sequence-number Wrong Sequence Number Label 2.0.0 to 2.4.4
esp.spi ESP SPI Unsigned integer, 4 bytes 1.0.0 to 2.4.4
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
  • • Fully integrated with Wireshark and AirPcap™
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More