Wireshark-dev: Re: [Wireshark-dev] Encapsulated IP
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 21 Sep 2010 11:24:00 -0700
On Sep 21, 2010, at 9:51 AM, Ronald Howe wrote:

> ok Can I then use SET_ADDRESS to put the Source and Destination fields back to the original IP address not the encapsulated Address? 

We make no guarantee whatsoever that dissectors for protocols running atop the encapsulated IP will work correctly if they run with the original IP addresses rather than the encapsulated IP addresses as the source and destination network-layer addresses.  See my previous message.