Coverage Report

Created: 2026-08-14 06:45

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-fortinet-fgcp.c
Line
Count
Source
1
/* packet-fortinet-fgcp.c
2
 * Routines for FortiGate Cluster Protocol dissection
3
 * Copyright 2023, Alexis La Goutte <alexis.lagoutte at gmail dot com>
4
 *
5
 * Wireshark - Network traffic analyzer
6
 * By Gerald Combs <gerald@wireshark.org>
7
 * Copyright 1998 Gerald Combs
8
 *
9
 * SPDX-License-Identifier: GPL-2.0-or-later
10
 *
11
 * No spec/doc is available based on reverse/analysis of protocol...
12
 *
13
 */
14
15
#include "config.h"
16
17
#include <wireshark.h>
18
19
#include <epan/packet.h>
20
#include <epan/expert.h>
21
#include <epan/prefs.h>
22
#include <epan/etypes.h>
23
#include <epan/tfs.h>
24
25
void proto_reg_handoff_fortinet_fgcp(void);
26
void proto_register_fortinet_fgcp(void);
27
28
static int proto_fortinet_fgcp_hb;
29
static int hf_fortinet_fgcp_hb_magic;
30
static int hf_fortinet_fgcp_hb_flag;
31
static int hf_fortinet_fgcp_hb_flag_b74;
32
static int hf_fortinet_fgcp_hb_flag_b3;
33
static int hf_fortinet_fgcp_hb_flag_b2;
34
static int hf_fortinet_fgcp_hb_flag_authentication;
35
static int hf_fortinet_fgcp_hb_flag_encryption;
36
static int hf_fortinet_fgcp_hb_mode;
37
static int hf_fortinet_fgcp_hb_gn;
38
static int hf_fortinet_fgcp_hb_group_id;
39
static int hf_fortinet_fgcp_hb_port;
40
static int hf_fortinet_fgcp_hb_revision;
41
static int hf_fortinet_fgcp_hb_sn;
42
static int hf_fortinet_fgcp_hb_payload_encrypted;
43
static int hf_fortinet_fgcp_hb_authentication;
44
45
static int hf_fortinet_fgcp_hb_tlv;
46
static int hf_fortinet_fgcp_hb_tlv_type;
47
static int hf_fortinet_fgcp_hb_tlv_length;
48
static int hf_fortinet_fgcp_hb_tlv_value;
49
static int hf_fortinet_fgcp_hb_tlv_vcluster_id;
50
static int hf_fortinet_fgcp_hb_tlv_priority;
51
static int hf_fortinet_fgcp_hb_tlv_override;
52
static int hf_fortinet_fgcp_hb_tlv_ha_checksum_global;
53
static int hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom;
54
static int hf_fortinet_fgcp_hb_tlv_ha_checksum_root;
55
static int hf_fortinet_fgcp_hb_tlv_interface_inventory;
56
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_interface;
57
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_number;
58
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_name;
59
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_mac;
60
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag;
61
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status;
62
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status;
63
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored;
64
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible;
65
static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74;
66
67
//static int hf_fortinet_fgcp_hb_unknown;
68
static int hf_fortinet_fgcp_hb_unknown_uint16;
69
70
static dissector_handle_t fortinet_fgcp_hb_handle;
71
72
static int ett_fortinet_fgcp_hb;
73
static int ett_fortinet_fgcp_hb_flag;
74
static int ett_fortinet_fgcp_hb_tlv;
75
static int ett_fortinet_fgcp_hb_tlv_interface;
76
static int ett_fortinet_fgcp_hb_tlv_interface_flag;
77
78
static int proto_fortinet_fgcp_session;
79
static int hf_fortinet_fgcp_session_magic;
80
static int hf_fortinet_fgcp_session_type;
81
82
static dissector_handle_t fortinet_fgcp_session_handle;
83
static dissector_handle_t ip_handle;
84
85
static int ett_fortinet_fgcp_session;
86
87
static const value_string fortinet_fgcp_hb_mode_vals[] = {
88
    { 0x1,            "A/A (Active/Active)"},
89
    { 0x2,            "A/P (Active/Passive)"},
90
    {0, NULL }
91
};
92
93
#define HB_TLV_END_OF_TLV       0x00
94
0
#define HB_TLV_VCLUSTER_ID      0x0B
95
1
#define HB_TLV_PRIORITY         0x0C
96
1
#define HB_TLV_OVERRIDE         0x0D
97
0
#define HB_TLV_INTERFACE_INVENTORY 0x2a
98
0
#define HB_TLV_HA_CHECKSUM      0x3C
99
100
static const value_string fortinet_fgcp_hb_tlv_vals[] = {
101
    { HB_TLV_END_OF_TLV, "End of TLV" },
102
    { HB_TLV_PRIORITY, "Port Priority" },
103
    { HB_TLV_OVERRIDE, "Override" },
104
    { HB_TLV_INTERFACE_INVENTORY, "Interface Inventory" },
105
    { HB_TLV_HA_CHECKSUM, "HA Checksum" },
106
    { 0, NULL }
107
};
108
109
110
static int
111
dissect_fortinet_fgcp_hb(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree,
112
        void *data _U_)
113
24
{
114
24
    proto_item *ti;
115
24
    proto_tree *fortinet_hb_tree;
116
24
    unsigned    offset = 0, length, auth_len=0;
117
24
    uint8_t     flags;
118
119
24
    col_set_str(pinfo->cinfo, COL_PROTOCOL, "FGCP-HB");
120
121
24
    col_add_fstr(pinfo->cinfo, COL_INFO, "Cluster: %s(%u) - monitor: %s - SN: %s",
122
24
                tvb_get_string_enc(pinfo->pool, tvb, offset+4, 32, ENC_ASCII), /* Group Name*/
123
24
                tvb_get_uint16(tvb, (offset+4+32+2), ENC_LITTLE_ENDIAN),  /* Group ID*/
124
24
                tvb_get_string_enc(pinfo->pool, tvb, offset+4+32+2+14, 16, ENC_ASCII), /* Port */
125
24
                tvb_get_string_enc(pinfo->pool, tvb, offset+4+32+2+14+16+2+2, 16, ENC_ASCII) /* Serial Number */);
126
127
24
    ti = proto_tree_add_item(tree, proto_fortinet_fgcp_hb, tvb, 0, -1, ENC_NA);
128
129
24
    fortinet_hb_tree = proto_item_add_subtree(ti, ett_fortinet_fgcp_hb);
130
131
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_magic, tvb, offset, 2, ENC_LITTLE_ENDIAN);
132
24
    offset += 2;
133
134
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_mode, tvb, offset, 1, ENC_NA);
135
24
    offset += 1;
136
137
24
    static int * const fortinet_fgcp_hb_flag[] = {
138
24
        &hf_fortinet_fgcp_hb_flag_b74,
139
24
        &hf_fortinet_fgcp_hb_flag_b3,
140
24
        &hf_fortinet_fgcp_hb_flag_b2,
141
24
        &hf_fortinet_fgcp_hb_flag_authentication,
142
24
        &hf_fortinet_fgcp_hb_flag_encryption,
143
24
        NULL
144
24
    };
145
146
24
    static int * const fortinet_fgcp_tlv_interface_flag[] = {
147
24
        &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status,
148
24
        &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status,
149
24
        &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored,
150
24
        &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible,
151
24
        &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74,
152
24
        NULL
153
24
    };
154
155
24
    proto_tree_add_bitmask(fortinet_hb_tree, tvb, offset, hf_fortinet_fgcp_hb_flag, ett_fortinet_fgcp_hb_flag,
156
24
                           fortinet_fgcp_hb_flag, ENC_NA);
157
24
    flags =  tvb_get_uint8(tvb, offset);
158
24
    offset += 1;
159
160
    /* Group Name */
161
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_gn, tvb, offset, 32, ENC_ASCII);
162
24
    offset += 32;
163
164
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
165
24
    offset += 2;
166
167
    /* Group Id */
168
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_group_id, tvb, offset, 2, ENC_LITTLE_ENDIAN);
169
24
    offset += 2;
170
171
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
172
24
    offset += 2;
173
174
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
175
24
    offset += 2;
176
177
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
178
24
    offset += 2;
179
180
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
181
24
    offset += 2;
182
183
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
184
24
    offset += 2;
185
186
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
187
24
    offset += 2;
188
189
    /* Heartbeat Port */
190
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_port, tvb, offset, 16, ENC_ASCII);
191
24
    offset += 16;
192
193
    /* Revision ? */
194
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_revision, tvb, offset, 2, ENC_LITTLE_ENDIAN);
195
24
    offset += 2;
196
197
    /* Hash/crc ? change after each revision*/
198
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN);
199
24
    offset += 2;
200
201
    /* Serial Number */
202
24
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_sn, tvb, offset, 16, ENC_ASCII);
203
24
    offset += 16;
204
205
24
    if (flags & 0x02) { /* Authentication ? */
206
        /* the payload finish with 32bits of authentication (hash ?) */
207
7
        auth_len = 32;
208
7
    }
209
210
24
    if (flags & 0x01) { /* Encrypted Payload ?*/
211
5
        length = tvb_reported_length_remaining(tvb, offset) - auth_len;
212
5
        proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_payload_encrypted, tvb, offset, length, ENC_NA);
213
5
        offset += length;
214
19
    } else {
215
19
        unsigned next_offset;
216
217
19
        length = tvb_reported_length_remaining(tvb, offset) - auth_len;
218
19
        next_offset = offset + length;
219
220
133
        while (offset < next_offset) {
221
128
                uint32_t type, len;
222
128
                proto_item *ti_tlv;
223
128
                proto_tree *tlv_tree;
224
225
128
                ti_tlv = proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_tlv, tvb, offset, 3, ENC_NA);
226
128
                tlv_tree = proto_item_add_subtree(ti_tlv, ett_fortinet_fgcp_hb_tlv);
227
128
                proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_type, tvb, offset, 2, ENC_LITTLE_ENDIAN, &type);
228
128
                offset += 2;
229
128
                proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_length, tvb, offset, 2, ENC_LITTLE_ENDIAN, &len);
230
128
                offset += 2;
231
232
128
                proto_item_append_text(ti_tlv, ": (t=%u,l=%d) %s", type, len, val_to_str_const(type, fortinet_fgcp_hb_tlv_vals ,"Unknown type") );
233
128
                proto_item_set_len(ti_tlv, 2 + 2 + len);
234
235
128
                proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_value, tvb, offset, len, ENC_NA);
236
128
                switch (type) {
237
0
                case HB_TLV_VCLUSTER_ID:{
238
0
                    uint32_t vcluster_id;
239
0
                    proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_vcluster_id, tvb, offset, 1, ENC_NA, &vcluster_id);
240
0
                    proto_item_append_text(ti_tlv, ": %u", vcluster_id);
241
0
                    offset += 1;
242
0
                    }
243
0
                break;
244
1
                case HB_TLV_PRIORITY:{
245
1
                    uint32_t priority;
246
1
                    proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_priority, tvb, offset, 1, ENC_NA, &priority);
247
1
                    proto_item_append_text(ti_tlv, ": %u", priority);
248
1
                    offset += 1;
249
1
                    }
250
1
                break;
251
1
                case HB_TLV_OVERRIDE:{
252
1
                    uint32_t override;
253
1
                    proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_override, tvb, offset, 1, ENC_NA, &override);
254
1
                    if (override){
255
0
                        proto_item_append_text(ti_tlv, ": True");
256
1
                    } else {
257
1
                        proto_item_append_text(ti_tlv, ": False");
258
1
                    }
259
1
                    offset += 1;
260
1
                    }
261
1
                break;
262
0
                case HB_TLV_HA_CHECKSUM:{
263
0
                    proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_global, tvb, offset, 16, ENC_NA);
264
0
                    offset += 16;
265
0
                    proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom, tvb, offset, 16, ENC_NA);
266
0
                    offset += 16;
267
0
                    proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_root, tvb, offset, 16, ENC_NA);
268
0
                    offset += 16;
269
0
                }
270
0
                break;
271
0
                case HB_TLV_INTERFACE_INVENTORY:{
272
0
                    tvbuff_t* compressed_tvb;
273
0
                    uint32_t number;
274
0
                    unsigned    coffset = 0;
275
0
                    proto_item *ti_interface;
276
0
                    proto_tree *interface_tree;
277
0
                    proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_number, tvb, offset, 2, ENC_LITTLE_ENDIAN, &number);
278
0
                    offset += 2;
279
0
                    compressed_tvb = tvb_child_uncompress_zlib(tvb, tvb, offset, len-2);
280
0
                    if (compressed_tvb) {
281
0
                        add_new_data_source(pinfo, compressed_tvb, "Decompressed Data");
282
0
                        proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory, compressed_tvb, 0, -1, ENC_NA);
283
0
                        while (number) {
284
0
                            ti_interface = proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_interface, compressed_tvb, coffset, 16+6+1, ENC_NA);
285
0
                            interface_tree = proto_item_add_subtree(ti_interface, ett_fortinet_fgcp_hb_tlv_interface);
286
0
                            proto_tree_add_item(interface_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_name, compressed_tvb, coffset, 16, ENC_ASCII);
287
0
                            proto_item_append_text(ti_interface, ": %s", tvb_get_stringz_enc(pinfo->pool, compressed_tvb, coffset, NULL, ENC_ASCII) );
288
0
                            coffset += 16;
289
0
                            proto_tree_add_item(interface_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_mac, compressed_tvb, coffset, 6, ENC_NA);
290
0
                            coffset += 6;
291
0
                            proto_tree_add_bitmask(interface_tree, compressed_tvb, coffset, hf_fortinet_fgcp_hb_tlv_interface_inventory_flag,
292
0
                                                   ett_fortinet_fgcp_hb_tlv_interface_flag, fortinet_fgcp_tlv_interface_flag, ENC_NA);
293
0
                            flags =  tvb_get_uint8(compressed_tvb, coffset);
294
0
                            if (flags & 0x01) {
295
0
                                proto_item_append_text(ti_interface, ", Admin Status: UP");
296
0
                            }
297
0
                            if (flags & 0x02) {
298
0
                                proto_item_append_text(ti_interface, ", Operation Status: UP");
299
0
                            }
300
0
                            if (flags & 0x04) {
301
0
                                proto_item_append_text(ti_interface, ", Link Monitored: Yes");
302
0
                            }
303
0
                            if (flags & 0x08) {
304
0
                                proto_item_append_text(ti_interface, ", HA Eligible: Yes");
305
0
                            }
306
0
                            coffset += 1;
307
0
                            number--;
308
0
                        }
309
310
0
                    }
311
0
                    offset += (len-2);
312
0
                }
313
0
                break;
314
315
112
                default:
316
112
                    offset += len;
317
112
                break;
318
128
                }
319
128
            }
320
19
    }
321
322
10
    if (auth_len) { /* Authentication ? */
323
2
        proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_authentication, tvb, offset, 32, ENC_NA);
324
2
        offset += 32;
325
2
    }
326
327
10
    return offset;
328
24
}
329
330
static int
331
dissect_fortinet_fgcp_session(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree,
332
        void *data _U_)
333
2
{
334
2
    proto_item *ti;
335
2
    proto_tree *fortinet_hb_tree;
336
2
    unsigned    offset = 0;
337
2
    tvbuff_t    *data_tvb;
338
339
2
    col_set_str(pinfo->cinfo, COL_PROTOCOL, "FGCP-SESSION");
340
341
2
    ti = proto_tree_add_item(tree, proto_fortinet_fgcp_session, tvb, 0, -1, ENC_NA);
342
343
2
    fortinet_hb_tree = proto_item_add_subtree(ti, ett_fortinet_fgcp_session);
344
345
2
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_session_magic, tvb, offset, 2, ENC_LITTLE_ENDIAN);
346
2
    offset += 2;
347
348
2
    proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_session_type, tvb, offset, 2, ENC_LITTLE_ENDIAN);
349
2
    offset += 2;
350
351
2
    data_tvb = tvb_new_subset_remaining(tvb, offset);
352
2
    call_dissector(ip_handle, data_tvb, pinfo, tree);
353
354
2
    return offset;
355
2
}
356
357
void
358
proto_register_fortinet_fgcp(void)
359
16
{
360
361
16
    static hf_register_info hf[] = {
362
        /* HeartBeat */
363
16
        { &hf_fortinet_fgcp_hb_magic,
364
16
            { "Magic Number", "fortinet_fgcp.hb.magic",
365
16
            FT_UINT16, BASE_HEX_DEC, NULL, 0x0,
366
16
            "Magic Number ?", HFILL }
367
16
        },
368
16
        { &hf_fortinet_fgcp_hb_flag,
369
16
            { "Flag", "fortinet_fgcp.hb.flag",
370
16
            FT_UINT8, BASE_HEX, NULL, 0x0,
371
16
            NULL, HFILL }
372
16
        },
373
16
        { &hf_fortinet_fgcp_hb_flag_b74,
374
16
            { "Bit 7 to 4", "fortinet_fgcp.hb.flag.b74",
375
16
            FT_UINT8, BASE_HEX, NULL, 0xF0,
376
16
            "Unknown", HFILL }
377
16
        },
378
16
        { &hf_fortinet_fgcp_hb_flag_b3,
379
16
            { "Bit b3", "fortinet_fgcp.hb.flag.b3",
380
16
            FT_UINT8, BASE_HEX, NULL, 0x08,
381
16
            "Unknown", HFILL }
382
16
        },
383
16
        { &hf_fortinet_fgcp_hb_flag_b2,
384
16
            { "Bit b2", "fortinet_fgcp.hb.flag.b2",
385
16
            FT_UINT8, BASE_HEX, NULL, 0x04,
386
16
            "Unknown", HFILL }
387
16
        },
388
16
        { &hf_fortinet_fgcp_hb_flag_authentication,
389
16
            { "Authentication", "fortinet_fgcp.hb.flag.authentication",
390
16
            FT_BOOLEAN, 8, NULL, 0x02,
391
16
            NULL, HFILL }
392
16
        },
393
16
        { &hf_fortinet_fgcp_hb_flag_encryption,
394
16
            { "Encryption", "fortinet_fgcp.hb.flag.encryption",
395
16
            FT_BOOLEAN, 8, NULL, 0x01,
396
16
            NULL, HFILL }
397
16
        },
398
16
        { &hf_fortinet_fgcp_hb_mode,
399
16
            { "Mode", "fortinet_fgcp.hb.mode",
400
16
            FT_UINT8, BASE_DEC, VALS(fortinet_fgcp_hb_mode_vals), 0x0,
401
16
            NULL, HFILL }
402
16
        },
403
16
        { &hf_fortinet_fgcp_hb_gn,
404
16
            { "Group Name", "fortinet_fgcp.hb.gn",
405
16
            FT_STRING, BASE_NONE, NULL, 0x0,
406
16
            NULL, HFILL }
407
16
        },
408
16
        { &hf_fortinet_fgcp_hb_group_id,
409
16
            { "Group Id", "fortinet_fgcp.hb.group_id",
410
16
            FT_UINT16, BASE_DEC, NULL, 0x0,
411
16
            NULL, HFILL }
412
16
        },
413
16
        { &hf_fortinet_fgcp_hb_port,
414
16
            { "Port", "fortinet_fgcp.hb.port",
415
16
            FT_STRING, BASE_NONE, NULL, 0x0,
416
16
            NULL, HFILL }
417
16
        },
418
16
        { &hf_fortinet_fgcp_hb_revision,
419
16
            { "Revision", "fortinet_fgcp.hb.revision",
420
16
            FT_UINT16, BASE_DEC, NULL, 0x0,
421
16
            "Number of revision config for HA", HFILL }
422
16
        },
423
16
        { &hf_fortinet_fgcp_hb_sn,
424
16
            { "Serial Number", "fortinet_fgcp.hb.sn",
425
16
            FT_STRING, BASE_NONE, NULL, 0x0,
426
16
            NULL, HFILL }
427
16
        },
428
16
        { &hf_fortinet_fgcp_hb_payload_encrypted,
429
16
            { "Payload (encrypted)", "fortinet_fgcp.hb.payload_encrypted",
430
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
431
16
            NULL, HFILL }
432
16
        },
433
16
        { &hf_fortinet_fgcp_hb_authentication,
434
16
            { "Authentication", "fortinet_fgcp.hb.authentication",
435
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
436
16
            NULL, HFILL }
437
16
        },
438
439
16
        { &hf_fortinet_fgcp_hb_tlv,
440
16
          { "TLV", "fortinet_fgcp.hb.tlv",
441
16
            FT_NONE, BASE_NONE, NULL, 0x0,
442
16
            NULL, HFILL }
443
16
        },
444
16
        { &hf_fortinet_fgcp_hb_tlv_type,
445
16
          { "Type", "fortinet_fgcp.hb.tlv.type",
446
16
            FT_UINT16, BASE_HEX, VALS(fortinet_fgcp_hb_tlv_vals), 0x0,
447
16
            NULL, HFILL }
448
16
        },
449
16
        { &hf_fortinet_fgcp_hb_tlv_length,
450
16
          { "Length", "fortinet_fgcp.hb.tlv.length",
451
16
            FT_UINT16, BASE_DEC, NULL, 0x0,
452
16
            NULL, HFILL }
453
16
        },
454
16
        { &hf_fortinet_fgcp_hb_tlv_value,
455
16
          { "Value", "fortinet_fgcp.hb.tlv.value",
456
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
457
16
            NULL, HFILL }
458
16
        },
459
460
16
        { &hf_fortinet_fgcp_hb_tlv_vcluster_id,
461
16
            { "Vcluster ID", "fortinet_fgcp.hb.tlv.vcluster_id",
462
16
            FT_UINT8, BASE_DEC, NULL, 0x0,
463
16
            NULL, HFILL }
464
16
        },
465
16
        { &hf_fortinet_fgcp_hb_tlv_priority,
466
16
            { "Port Priority", "fortinet_fgcp.hb.tlv.priority",
467
16
            FT_UINT8, BASE_DEC, NULL, 0x0,
468
16
            NULL, HFILL }
469
16
        },
470
16
        { &hf_fortinet_fgcp_hb_tlv_override,
471
16
            { "Override", "fortinet_fgcp.hb.tlv.override",
472
16
            FT_UINT8, BASE_DEC, NULL, 0x0,
473
16
            NULL, HFILL }
474
16
        },
475
16
        { &hf_fortinet_fgcp_hb_tlv_ha_checksum_global,
476
16
            { "HA Checksum Global", "fortinet_fgcp.hb.tlv.ha_checksum.global",
477
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
478
16
            NULL, HFILL }
479
16
        },
480
16
        { &hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom,
481
16
            { "HA Checksum VDOM", "fortinet_fgcp.hb.tlv.ha_checksum.vdom",
482
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
483
16
            NULL, HFILL }
484
16
        },
485
16
        { &hf_fortinet_fgcp_hb_tlv_ha_checksum_root,
486
16
            { "HA Checksum Root", "fortinet_fgcp.hb.tlv.ha_checksum.root",
487
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
488
16
            NULL, HFILL }
489
16
        },
490
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory,
491
16
            { "Interface Inventory", "fortinet_fgcp.hb.tlv.interface_inventory",
492
16
            FT_BYTES, BASE_NONE, NULL, 0x0,
493
16
            NULL, HFILL }
494
16
        },
495
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_interface,
496
16
            { "Interface", "fortinet_fgcp.hb.tlv.interface_inventory.interface",
497
16
            FT_NONE, BASE_NONE, NULL, 0x0,
498
16
            NULL, HFILL }
499
16
        },
500
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_number,
501
16
            { "Number of Interfaces", "fortinet_fgcp.hb.tlv.interface_inventory.number",
502
16
            FT_UINT16, BASE_DEC, NULL, 0x0,
503
16
            NULL, HFILL }
504
16
        },
505
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_name,
506
16
            { "Name", "fortinet_fgcp.hb.tlv.interface_inventory.name",
507
16
            FT_STRINGZ, BASE_NONE, NULL, 0x0,
508
16
            NULL, HFILL }
509
16
        },
510
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_mac,
511
16
            { "Mac", "fortinet_fgcp.hb.tlv.interface_inventory.mac",
512
16
            FT_ETHER, BASE_NONE, NULL, 0x0,
513
16
            NULL, HFILL }
514
16
        },
515
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag,
516
16
            { "Flag", "fortinet_fgcp.hb.tlv.interface_inventory.flag",
517
16
            FT_UINT8, BASE_HEX, NULL, 0x0,
518
16
            NULL, HFILL }
519
16
        },
520
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status,
521
16
            { "Admin Status", "fortinet_fgcp.hb.tlv.interface_inventory.flag.admin_status",
522
16
            FT_BOOLEAN, 8, TFS(&tfs_up_down), 0x01,
523
16
            NULL, HFILL }
524
16
        },
525
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status,
526
16
            { "Operation Status", "fortinet_fgcp.hb.tlv.interface_inventory.flag.operation_status",
527
16
            FT_BOOLEAN, 8, TFS(&tfs_up_down), 0x02,
528
16
            NULL, HFILL }
529
16
        },
530
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored,
531
16
            { "Link Monitored", "fortinet_fgcp.hb.tlv.interface_inventory.flag.link_monitored",
532
16
            FT_BOOLEAN, 8, NULL, 0x04,
533
16
            NULL, HFILL }
534
16
        },
535
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible,
536
16
            { "HA Eligible", "fortinet_fgcp.hb.tlv.interface_inventory.flag.ha_eligbile",
537
16
            FT_BOOLEAN, 8, NULL, 0x08,
538
16
            NULL, HFILL }
539
16
        },
540
16
        { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74,
541
16
            { "Reserved", "fortinet_fgcp.hb.tlv.interface_inventory.flag.b74",
542
16
            FT_UINT8, BASE_HEX, NULL, 0xF0,
543
16
            "Bit 7 to 4", HFILL }
544
16
        },
545
        /*
546
        { &hf_fortinet_fgcp_hb_unknown,
547
            { "Unknown", "fortinet_fgcp.hb.unknown",
548
            FT_BYTES, BASE_NONE, NULL, 0x0,
549
            "Always NULL ?", HFILL }
550
        },
551
        */
552
16
        { &hf_fortinet_fgcp_hb_unknown_uint16,
553
16
            { "Unknown", "fortinet_fgcp.hb.unknown.uint16",
554
16
            FT_UINT16, BASE_DEC_HEX, NULL, 0x0,
555
16
            NULL, HFILL }
556
16
        },
557
558
        /* Session */
559
16
        { &hf_fortinet_fgcp_session_magic,
560
16
            { "Magic Number", "fortinet_fgcp.session.magic",
561
16
            FT_UINT16, BASE_HEX_DEC, NULL, 0x0,
562
16
            "Magic Number ?", HFILL }
563
16
        },
564
16
        { &hf_fortinet_fgcp_session_type,
565
16
            { "Type", "fortinet_fgcp.session.type",
566
16
            FT_UINT16, BASE_HEX, NULL, 0x0,
567
16
            NULL, HFILL }
568
16
        },
569
16
    };
570
571
    /* Setup protocol subtree array */
572
16
    static int *ett[] = {
573
16
        &ett_fortinet_fgcp_hb,
574
16
        &ett_fortinet_fgcp_hb_flag,
575
16
        &ett_fortinet_fgcp_hb_tlv,
576
16
        &ett_fortinet_fgcp_hb_tlv_interface,
577
16
        &ett_fortinet_fgcp_hb_tlv_interface_flag,
578
16
        &ett_fortinet_fgcp_session,
579
16
    };
580
581
    /* Register the protocol name and description */
582
16
    proto_fortinet_fgcp_hb = proto_register_protocol("FortiGate Cluster Protocol - HeartBeat",
583
16
            "fortinet_fgcp_hb", "fortinet_fgcp_hb");
584
585
16
    proto_fortinet_fgcp_session = proto_register_protocol("FortiGate Cluster Protocol - Session",
586
16
            "fortinet_fgcp_session", "fortinet_fgcp_session");
587
588
    /* Required function calls to register the header fields and subtrees */
589
16
    proto_register_field_array(proto_fortinet_fgcp_hb, hf, array_length(hf));
590
16
    proto_register_subtree_array(ett, array_length(ett));
591
592
16
    fortinet_fgcp_hb_handle = register_dissector("fortinet_fgcp_hb", dissect_fortinet_fgcp_hb,
593
16
            proto_fortinet_fgcp_hb);
594
595
16
    fortinet_fgcp_session_handle = register_dissector("fortinet_fgcp_session", dissect_fortinet_fgcp_session,
596
16
            proto_fortinet_fgcp_session);
597
598
16
}
599
600
601
void
602
proto_reg_handoff_fortinet_fgcp(void)
603
16
{
604
16
      dissector_add_uint("ethertype", ETHERTYPE_FORTINET_FGCP_HB, fortinet_fgcp_hb_handle);
605
16
      dissector_add_uint("ethertype", ETHERTYPE_FORTINET_FGCP_SESSION, fortinet_fgcp_session_handle);
606
607
16
      ip_handle  = find_dissector_add_dependency("ip", proto_fortinet_fgcp_session);
608
16
}
609
610
/*
611
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
612
 *
613
 * Local variables:
614
 * c-basic-offset: 4
615
 * tab-width: 8
616
 * indent-tabs-mode: nil
617
 * End:
618
 *
619
 * vi: set shiftwidth=4 tabstop=8 expandtab:
620
 * :indentSize=4:tabSize=8:noTabs=true:
621
 */