/src/wireshark/epan/dissectors/packet-fortinet-fgcp.c
Line | Count | Source |
1 | | /* packet-fortinet-fgcp.c |
2 | | * Routines for FortiGate Cluster Protocol dissection |
3 | | * Copyright 2023, Alexis La Goutte <alexis.lagoutte at gmail dot com> |
4 | | * |
5 | | * Wireshark - Network traffic analyzer |
6 | | * By Gerald Combs <gerald@wireshark.org> |
7 | | * Copyright 1998 Gerald Combs |
8 | | * |
9 | | * SPDX-License-Identifier: GPL-2.0-or-later |
10 | | * |
11 | | * No spec/doc is available based on reverse/analysis of protocol... |
12 | | * |
13 | | */ |
14 | | |
15 | | #include "config.h" |
16 | | |
17 | | #include <wireshark.h> |
18 | | |
19 | | #include <epan/packet.h> |
20 | | #include <epan/expert.h> |
21 | | #include <epan/prefs.h> |
22 | | #include <epan/etypes.h> |
23 | | #include <epan/tfs.h> |
24 | | |
25 | | void proto_reg_handoff_fortinet_fgcp(void); |
26 | | void proto_register_fortinet_fgcp(void); |
27 | | |
28 | | static int proto_fortinet_fgcp_hb; |
29 | | static int hf_fortinet_fgcp_hb_magic; |
30 | | static int hf_fortinet_fgcp_hb_flag; |
31 | | static int hf_fortinet_fgcp_hb_flag_b74; |
32 | | static int hf_fortinet_fgcp_hb_flag_b3; |
33 | | static int hf_fortinet_fgcp_hb_flag_b2; |
34 | | static int hf_fortinet_fgcp_hb_flag_authentication; |
35 | | static int hf_fortinet_fgcp_hb_flag_encryption; |
36 | | static int hf_fortinet_fgcp_hb_mode; |
37 | | static int hf_fortinet_fgcp_hb_gn; |
38 | | static int hf_fortinet_fgcp_hb_group_id; |
39 | | static int hf_fortinet_fgcp_hb_port; |
40 | | static int hf_fortinet_fgcp_hb_revision; |
41 | | static int hf_fortinet_fgcp_hb_sn; |
42 | | static int hf_fortinet_fgcp_hb_payload_encrypted; |
43 | | static int hf_fortinet_fgcp_hb_authentication; |
44 | | |
45 | | static int hf_fortinet_fgcp_hb_tlv; |
46 | | static int hf_fortinet_fgcp_hb_tlv_type; |
47 | | static int hf_fortinet_fgcp_hb_tlv_length; |
48 | | static int hf_fortinet_fgcp_hb_tlv_value; |
49 | | static int hf_fortinet_fgcp_hb_tlv_vcluster_id; |
50 | | static int hf_fortinet_fgcp_hb_tlv_priority; |
51 | | static int hf_fortinet_fgcp_hb_tlv_override; |
52 | | static int hf_fortinet_fgcp_hb_tlv_ha_checksum_global; |
53 | | static int hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom; |
54 | | static int hf_fortinet_fgcp_hb_tlv_ha_checksum_root; |
55 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory; |
56 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_interface; |
57 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_number; |
58 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_name; |
59 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_mac; |
60 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag; |
61 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status; |
62 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status; |
63 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored; |
64 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible; |
65 | | static int hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74; |
66 | | |
67 | | //static int hf_fortinet_fgcp_hb_unknown; |
68 | | static int hf_fortinet_fgcp_hb_unknown_uint16; |
69 | | |
70 | | static dissector_handle_t fortinet_fgcp_hb_handle; |
71 | | |
72 | | static int ett_fortinet_fgcp_hb; |
73 | | static int ett_fortinet_fgcp_hb_flag; |
74 | | static int ett_fortinet_fgcp_hb_tlv; |
75 | | static int ett_fortinet_fgcp_hb_tlv_interface; |
76 | | static int ett_fortinet_fgcp_hb_tlv_interface_flag; |
77 | | |
78 | | static int proto_fortinet_fgcp_session; |
79 | | static int hf_fortinet_fgcp_session_magic; |
80 | | static int hf_fortinet_fgcp_session_type; |
81 | | |
82 | | static dissector_handle_t fortinet_fgcp_session_handle; |
83 | | static dissector_handle_t ip_handle; |
84 | | |
85 | | static int ett_fortinet_fgcp_session; |
86 | | |
87 | | static const value_string fortinet_fgcp_hb_mode_vals[] = { |
88 | | { 0x1, "A/A (Active/Active)"}, |
89 | | { 0x2, "A/P (Active/Passive)"}, |
90 | | {0, NULL } |
91 | | }; |
92 | | |
93 | | #define HB_TLV_END_OF_TLV 0x00 |
94 | 0 | #define HB_TLV_VCLUSTER_ID 0x0B |
95 | 1 | #define HB_TLV_PRIORITY 0x0C |
96 | 1 | #define HB_TLV_OVERRIDE 0x0D |
97 | 0 | #define HB_TLV_INTERFACE_INVENTORY 0x2a |
98 | 0 | #define HB_TLV_HA_CHECKSUM 0x3C |
99 | | |
100 | | static const value_string fortinet_fgcp_hb_tlv_vals[] = { |
101 | | { HB_TLV_END_OF_TLV, "End of TLV" }, |
102 | | { HB_TLV_PRIORITY, "Port Priority" }, |
103 | | { HB_TLV_OVERRIDE, "Override" }, |
104 | | { HB_TLV_INTERFACE_INVENTORY, "Interface Inventory" }, |
105 | | { HB_TLV_HA_CHECKSUM, "HA Checksum" }, |
106 | | { 0, NULL } |
107 | | }; |
108 | | |
109 | | |
110 | | static int |
111 | | dissect_fortinet_fgcp_hb(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, |
112 | | void *data _U_) |
113 | 24 | { |
114 | 24 | proto_item *ti; |
115 | 24 | proto_tree *fortinet_hb_tree; |
116 | 24 | unsigned offset = 0, length, auth_len=0; |
117 | 24 | uint8_t flags; |
118 | | |
119 | 24 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "FGCP-HB"); |
120 | | |
121 | 24 | col_add_fstr(pinfo->cinfo, COL_INFO, "Cluster: %s(%u) - monitor: %s - SN: %s", |
122 | 24 | tvb_get_string_enc(pinfo->pool, tvb, offset+4, 32, ENC_ASCII), /* Group Name*/ |
123 | 24 | tvb_get_uint16(tvb, (offset+4+32+2), ENC_LITTLE_ENDIAN), /* Group ID*/ |
124 | 24 | tvb_get_string_enc(pinfo->pool, tvb, offset+4+32+2+14, 16, ENC_ASCII), /* Port */ |
125 | 24 | tvb_get_string_enc(pinfo->pool, tvb, offset+4+32+2+14+16+2+2, 16, ENC_ASCII) /* Serial Number */); |
126 | | |
127 | 24 | ti = proto_tree_add_item(tree, proto_fortinet_fgcp_hb, tvb, 0, -1, ENC_NA); |
128 | | |
129 | 24 | fortinet_hb_tree = proto_item_add_subtree(ti, ett_fortinet_fgcp_hb); |
130 | | |
131 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_magic, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
132 | 24 | offset += 2; |
133 | | |
134 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_mode, tvb, offset, 1, ENC_NA); |
135 | 24 | offset += 1; |
136 | | |
137 | 24 | static int * const fortinet_fgcp_hb_flag[] = { |
138 | 24 | &hf_fortinet_fgcp_hb_flag_b74, |
139 | 24 | &hf_fortinet_fgcp_hb_flag_b3, |
140 | 24 | &hf_fortinet_fgcp_hb_flag_b2, |
141 | 24 | &hf_fortinet_fgcp_hb_flag_authentication, |
142 | 24 | &hf_fortinet_fgcp_hb_flag_encryption, |
143 | 24 | NULL |
144 | 24 | }; |
145 | | |
146 | 24 | static int * const fortinet_fgcp_tlv_interface_flag[] = { |
147 | 24 | &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status, |
148 | 24 | &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status, |
149 | 24 | &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored, |
150 | 24 | &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible, |
151 | 24 | &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74, |
152 | 24 | NULL |
153 | 24 | }; |
154 | | |
155 | 24 | proto_tree_add_bitmask(fortinet_hb_tree, tvb, offset, hf_fortinet_fgcp_hb_flag, ett_fortinet_fgcp_hb_flag, |
156 | 24 | fortinet_fgcp_hb_flag, ENC_NA); |
157 | 24 | flags = tvb_get_uint8(tvb, offset); |
158 | 24 | offset += 1; |
159 | | |
160 | | /* Group Name */ |
161 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_gn, tvb, offset, 32, ENC_ASCII); |
162 | 24 | offset += 32; |
163 | | |
164 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
165 | 24 | offset += 2; |
166 | | |
167 | | /* Group Id */ |
168 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_group_id, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
169 | 24 | offset += 2; |
170 | | |
171 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
172 | 24 | offset += 2; |
173 | | |
174 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
175 | 24 | offset += 2; |
176 | | |
177 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
178 | 24 | offset += 2; |
179 | | |
180 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
181 | 24 | offset += 2; |
182 | | |
183 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
184 | 24 | offset += 2; |
185 | | |
186 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
187 | 24 | offset += 2; |
188 | | |
189 | | /* Heartbeat Port */ |
190 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_port, tvb, offset, 16, ENC_ASCII); |
191 | 24 | offset += 16; |
192 | | |
193 | | /* Revision ? */ |
194 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_revision, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
195 | 24 | offset += 2; |
196 | | |
197 | | /* Hash/crc ? change after each revision*/ |
198 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_unknown_uint16, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
199 | 24 | offset += 2; |
200 | | |
201 | | /* Serial Number */ |
202 | 24 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_sn, tvb, offset, 16, ENC_ASCII); |
203 | 24 | offset += 16; |
204 | | |
205 | 24 | if (flags & 0x02) { /* Authentication ? */ |
206 | | /* the payload finish with 32bits of authentication (hash ?) */ |
207 | 7 | auth_len = 32; |
208 | 7 | } |
209 | | |
210 | 24 | if (flags & 0x01) { /* Encrypted Payload ?*/ |
211 | 5 | length = tvb_reported_length_remaining(tvb, offset) - auth_len; |
212 | 5 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_payload_encrypted, tvb, offset, length, ENC_NA); |
213 | 5 | offset += length; |
214 | 19 | } else { |
215 | 19 | unsigned next_offset; |
216 | | |
217 | 19 | length = tvb_reported_length_remaining(tvb, offset) - auth_len; |
218 | 19 | next_offset = offset + length; |
219 | | |
220 | 133 | while (offset < next_offset) { |
221 | 128 | uint32_t type, len; |
222 | 128 | proto_item *ti_tlv; |
223 | 128 | proto_tree *tlv_tree; |
224 | | |
225 | 128 | ti_tlv = proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_tlv, tvb, offset, 3, ENC_NA); |
226 | 128 | tlv_tree = proto_item_add_subtree(ti_tlv, ett_fortinet_fgcp_hb_tlv); |
227 | 128 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_type, tvb, offset, 2, ENC_LITTLE_ENDIAN, &type); |
228 | 128 | offset += 2; |
229 | 128 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_length, tvb, offset, 2, ENC_LITTLE_ENDIAN, &len); |
230 | 128 | offset += 2; |
231 | | |
232 | 128 | proto_item_append_text(ti_tlv, ": (t=%u,l=%d) %s", type, len, val_to_str_const(type, fortinet_fgcp_hb_tlv_vals ,"Unknown type") ); |
233 | 128 | proto_item_set_len(ti_tlv, 2 + 2 + len); |
234 | | |
235 | 128 | proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_value, tvb, offset, len, ENC_NA); |
236 | 128 | switch (type) { |
237 | 0 | case HB_TLV_VCLUSTER_ID:{ |
238 | 0 | uint32_t vcluster_id; |
239 | 0 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_vcluster_id, tvb, offset, 1, ENC_NA, &vcluster_id); |
240 | 0 | proto_item_append_text(ti_tlv, ": %u", vcluster_id); |
241 | 0 | offset += 1; |
242 | 0 | } |
243 | 0 | break; |
244 | 1 | case HB_TLV_PRIORITY:{ |
245 | 1 | uint32_t priority; |
246 | 1 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_priority, tvb, offset, 1, ENC_NA, &priority); |
247 | 1 | proto_item_append_text(ti_tlv, ": %u", priority); |
248 | 1 | offset += 1; |
249 | 1 | } |
250 | 1 | break; |
251 | 1 | case HB_TLV_OVERRIDE:{ |
252 | 1 | uint32_t override; |
253 | 1 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_override, tvb, offset, 1, ENC_NA, &override); |
254 | 1 | if (override){ |
255 | 0 | proto_item_append_text(ti_tlv, ": True"); |
256 | 1 | } else { |
257 | 1 | proto_item_append_text(ti_tlv, ": False"); |
258 | 1 | } |
259 | 1 | offset += 1; |
260 | 1 | } |
261 | 1 | break; |
262 | 0 | case HB_TLV_HA_CHECKSUM:{ |
263 | 0 | proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_global, tvb, offset, 16, ENC_NA); |
264 | 0 | offset += 16; |
265 | 0 | proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom, tvb, offset, 16, ENC_NA); |
266 | 0 | offset += 16; |
267 | 0 | proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_ha_checksum_root, tvb, offset, 16, ENC_NA); |
268 | 0 | offset += 16; |
269 | 0 | } |
270 | 0 | break; |
271 | 0 | case HB_TLV_INTERFACE_INVENTORY:{ |
272 | 0 | tvbuff_t* compressed_tvb; |
273 | 0 | uint32_t number; |
274 | 0 | unsigned coffset = 0; |
275 | 0 | proto_item *ti_interface; |
276 | 0 | proto_tree *interface_tree; |
277 | 0 | proto_tree_add_item_ret_uint(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_number, tvb, offset, 2, ENC_LITTLE_ENDIAN, &number); |
278 | 0 | offset += 2; |
279 | 0 | compressed_tvb = tvb_child_uncompress_zlib(tvb, tvb, offset, len-2); |
280 | 0 | if (compressed_tvb) { |
281 | 0 | add_new_data_source(pinfo, compressed_tvb, "Decompressed Data"); |
282 | 0 | proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory, compressed_tvb, 0, -1, ENC_NA); |
283 | 0 | while (number) { |
284 | 0 | ti_interface = proto_tree_add_item(tlv_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_interface, compressed_tvb, coffset, 16+6+1, ENC_NA); |
285 | 0 | interface_tree = proto_item_add_subtree(ti_interface, ett_fortinet_fgcp_hb_tlv_interface); |
286 | 0 | proto_tree_add_item(interface_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_name, compressed_tvb, coffset, 16, ENC_ASCII); |
287 | 0 | proto_item_append_text(ti_interface, ": %s", tvb_get_stringz_enc(pinfo->pool, compressed_tvb, coffset, NULL, ENC_ASCII) ); |
288 | 0 | coffset += 16; |
289 | 0 | proto_tree_add_item(interface_tree, hf_fortinet_fgcp_hb_tlv_interface_inventory_mac, compressed_tvb, coffset, 6, ENC_NA); |
290 | 0 | coffset += 6; |
291 | 0 | proto_tree_add_bitmask(interface_tree, compressed_tvb, coffset, hf_fortinet_fgcp_hb_tlv_interface_inventory_flag, |
292 | 0 | ett_fortinet_fgcp_hb_tlv_interface_flag, fortinet_fgcp_tlv_interface_flag, ENC_NA); |
293 | 0 | flags = tvb_get_uint8(compressed_tvb, coffset); |
294 | 0 | if (flags & 0x01) { |
295 | 0 | proto_item_append_text(ti_interface, ", Admin Status: UP"); |
296 | 0 | } |
297 | 0 | if (flags & 0x02) { |
298 | 0 | proto_item_append_text(ti_interface, ", Operation Status: UP"); |
299 | 0 | } |
300 | 0 | if (flags & 0x04) { |
301 | 0 | proto_item_append_text(ti_interface, ", Link Monitored: Yes"); |
302 | 0 | } |
303 | 0 | if (flags & 0x08) { |
304 | 0 | proto_item_append_text(ti_interface, ", HA Eligible: Yes"); |
305 | 0 | } |
306 | 0 | coffset += 1; |
307 | 0 | number--; |
308 | 0 | } |
309 | |
|
310 | 0 | } |
311 | 0 | offset += (len-2); |
312 | 0 | } |
313 | 0 | break; |
314 | | |
315 | 112 | default: |
316 | 112 | offset += len; |
317 | 112 | break; |
318 | 128 | } |
319 | 128 | } |
320 | 19 | } |
321 | | |
322 | 10 | if (auth_len) { /* Authentication ? */ |
323 | 2 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_hb_authentication, tvb, offset, 32, ENC_NA); |
324 | 2 | offset += 32; |
325 | 2 | } |
326 | | |
327 | 10 | return offset; |
328 | 24 | } |
329 | | |
330 | | static int |
331 | | dissect_fortinet_fgcp_session(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, |
332 | | void *data _U_) |
333 | 2 | { |
334 | 2 | proto_item *ti; |
335 | 2 | proto_tree *fortinet_hb_tree; |
336 | 2 | unsigned offset = 0; |
337 | 2 | tvbuff_t *data_tvb; |
338 | | |
339 | 2 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "FGCP-SESSION"); |
340 | | |
341 | 2 | ti = proto_tree_add_item(tree, proto_fortinet_fgcp_session, tvb, 0, -1, ENC_NA); |
342 | | |
343 | 2 | fortinet_hb_tree = proto_item_add_subtree(ti, ett_fortinet_fgcp_session); |
344 | | |
345 | 2 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_session_magic, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
346 | 2 | offset += 2; |
347 | | |
348 | 2 | proto_tree_add_item(fortinet_hb_tree, hf_fortinet_fgcp_session_type, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
349 | 2 | offset += 2; |
350 | | |
351 | 2 | data_tvb = tvb_new_subset_remaining(tvb, offset); |
352 | 2 | call_dissector(ip_handle, data_tvb, pinfo, tree); |
353 | | |
354 | 2 | return offset; |
355 | 2 | } |
356 | | |
357 | | void |
358 | | proto_register_fortinet_fgcp(void) |
359 | 16 | { |
360 | | |
361 | 16 | static hf_register_info hf[] = { |
362 | | /* HeartBeat */ |
363 | 16 | { &hf_fortinet_fgcp_hb_magic, |
364 | 16 | { "Magic Number", "fortinet_fgcp.hb.magic", |
365 | 16 | FT_UINT16, BASE_HEX_DEC, NULL, 0x0, |
366 | 16 | "Magic Number ?", HFILL } |
367 | 16 | }, |
368 | 16 | { &hf_fortinet_fgcp_hb_flag, |
369 | 16 | { "Flag", "fortinet_fgcp.hb.flag", |
370 | 16 | FT_UINT8, BASE_HEX, NULL, 0x0, |
371 | 16 | NULL, HFILL } |
372 | 16 | }, |
373 | 16 | { &hf_fortinet_fgcp_hb_flag_b74, |
374 | 16 | { "Bit 7 to 4", "fortinet_fgcp.hb.flag.b74", |
375 | 16 | FT_UINT8, BASE_HEX, NULL, 0xF0, |
376 | 16 | "Unknown", HFILL } |
377 | 16 | }, |
378 | 16 | { &hf_fortinet_fgcp_hb_flag_b3, |
379 | 16 | { "Bit b3", "fortinet_fgcp.hb.flag.b3", |
380 | 16 | FT_UINT8, BASE_HEX, NULL, 0x08, |
381 | 16 | "Unknown", HFILL } |
382 | 16 | }, |
383 | 16 | { &hf_fortinet_fgcp_hb_flag_b2, |
384 | 16 | { "Bit b2", "fortinet_fgcp.hb.flag.b2", |
385 | 16 | FT_UINT8, BASE_HEX, NULL, 0x04, |
386 | 16 | "Unknown", HFILL } |
387 | 16 | }, |
388 | 16 | { &hf_fortinet_fgcp_hb_flag_authentication, |
389 | 16 | { "Authentication", "fortinet_fgcp.hb.flag.authentication", |
390 | 16 | FT_BOOLEAN, 8, NULL, 0x02, |
391 | 16 | NULL, HFILL } |
392 | 16 | }, |
393 | 16 | { &hf_fortinet_fgcp_hb_flag_encryption, |
394 | 16 | { "Encryption", "fortinet_fgcp.hb.flag.encryption", |
395 | 16 | FT_BOOLEAN, 8, NULL, 0x01, |
396 | 16 | NULL, HFILL } |
397 | 16 | }, |
398 | 16 | { &hf_fortinet_fgcp_hb_mode, |
399 | 16 | { "Mode", "fortinet_fgcp.hb.mode", |
400 | 16 | FT_UINT8, BASE_DEC, VALS(fortinet_fgcp_hb_mode_vals), 0x0, |
401 | 16 | NULL, HFILL } |
402 | 16 | }, |
403 | 16 | { &hf_fortinet_fgcp_hb_gn, |
404 | 16 | { "Group Name", "fortinet_fgcp.hb.gn", |
405 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, |
406 | 16 | NULL, HFILL } |
407 | 16 | }, |
408 | 16 | { &hf_fortinet_fgcp_hb_group_id, |
409 | 16 | { "Group Id", "fortinet_fgcp.hb.group_id", |
410 | 16 | FT_UINT16, BASE_DEC, NULL, 0x0, |
411 | 16 | NULL, HFILL } |
412 | 16 | }, |
413 | 16 | { &hf_fortinet_fgcp_hb_port, |
414 | 16 | { "Port", "fortinet_fgcp.hb.port", |
415 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, |
416 | 16 | NULL, HFILL } |
417 | 16 | }, |
418 | 16 | { &hf_fortinet_fgcp_hb_revision, |
419 | 16 | { "Revision", "fortinet_fgcp.hb.revision", |
420 | 16 | FT_UINT16, BASE_DEC, NULL, 0x0, |
421 | 16 | "Number of revision config for HA", HFILL } |
422 | 16 | }, |
423 | 16 | { &hf_fortinet_fgcp_hb_sn, |
424 | 16 | { "Serial Number", "fortinet_fgcp.hb.sn", |
425 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, |
426 | 16 | NULL, HFILL } |
427 | 16 | }, |
428 | 16 | { &hf_fortinet_fgcp_hb_payload_encrypted, |
429 | 16 | { "Payload (encrypted)", "fortinet_fgcp.hb.payload_encrypted", |
430 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
431 | 16 | NULL, HFILL } |
432 | 16 | }, |
433 | 16 | { &hf_fortinet_fgcp_hb_authentication, |
434 | 16 | { "Authentication", "fortinet_fgcp.hb.authentication", |
435 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
436 | 16 | NULL, HFILL } |
437 | 16 | }, |
438 | | |
439 | 16 | { &hf_fortinet_fgcp_hb_tlv, |
440 | 16 | { "TLV", "fortinet_fgcp.hb.tlv", |
441 | 16 | FT_NONE, BASE_NONE, NULL, 0x0, |
442 | 16 | NULL, HFILL } |
443 | 16 | }, |
444 | 16 | { &hf_fortinet_fgcp_hb_tlv_type, |
445 | 16 | { "Type", "fortinet_fgcp.hb.tlv.type", |
446 | 16 | FT_UINT16, BASE_HEX, VALS(fortinet_fgcp_hb_tlv_vals), 0x0, |
447 | 16 | NULL, HFILL } |
448 | 16 | }, |
449 | 16 | { &hf_fortinet_fgcp_hb_tlv_length, |
450 | 16 | { "Length", "fortinet_fgcp.hb.tlv.length", |
451 | 16 | FT_UINT16, BASE_DEC, NULL, 0x0, |
452 | 16 | NULL, HFILL } |
453 | 16 | }, |
454 | 16 | { &hf_fortinet_fgcp_hb_tlv_value, |
455 | 16 | { "Value", "fortinet_fgcp.hb.tlv.value", |
456 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
457 | 16 | NULL, HFILL } |
458 | 16 | }, |
459 | | |
460 | 16 | { &hf_fortinet_fgcp_hb_tlv_vcluster_id, |
461 | 16 | { "Vcluster ID", "fortinet_fgcp.hb.tlv.vcluster_id", |
462 | 16 | FT_UINT8, BASE_DEC, NULL, 0x0, |
463 | 16 | NULL, HFILL } |
464 | 16 | }, |
465 | 16 | { &hf_fortinet_fgcp_hb_tlv_priority, |
466 | 16 | { "Port Priority", "fortinet_fgcp.hb.tlv.priority", |
467 | 16 | FT_UINT8, BASE_DEC, NULL, 0x0, |
468 | 16 | NULL, HFILL } |
469 | 16 | }, |
470 | 16 | { &hf_fortinet_fgcp_hb_tlv_override, |
471 | 16 | { "Override", "fortinet_fgcp.hb.tlv.override", |
472 | 16 | FT_UINT8, BASE_DEC, NULL, 0x0, |
473 | 16 | NULL, HFILL } |
474 | 16 | }, |
475 | 16 | { &hf_fortinet_fgcp_hb_tlv_ha_checksum_global, |
476 | 16 | { "HA Checksum Global", "fortinet_fgcp.hb.tlv.ha_checksum.global", |
477 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
478 | 16 | NULL, HFILL } |
479 | 16 | }, |
480 | 16 | { &hf_fortinet_fgcp_hb_tlv_ha_checksum_vdom, |
481 | 16 | { "HA Checksum VDOM", "fortinet_fgcp.hb.tlv.ha_checksum.vdom", |
482 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
483 | 16 | NULL, HFILL } |
484 | 16 | }, |
485 | 16 | { &hf_fortinet_fgcp_hb_tlv_ha_checksum_root, |
486 | 16 | { "HA Checksum Root", "fortinet_fgcp.hb.tlv.ha_checksum.root", |
487 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
488 | 16 | NULL, HFILL } |
489 | 16 | }, |
490 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory, |
491 | 16 | { "Interface Inventory", "fortinet_fgcp.hb.tlv.interface_inventory", |
492 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
493 | 16 | NULL, HFILL } |
494 | 16 | }, |
495 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_interface, |
496 | 16 | { "Interface", "fortinet_fgcp.hb.tlv.interface_inventory.interface", |
497 | 16 | FT_NONE, BASE_NONE, NULL, 0x0, |
498 | 16 | NULL, HFILL } |
499 | 16 | }, |
500 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_number, |
501 | 16 | { "Number of Interfaces", "fortinet_fgcp.hb.tlv.interface_inventory.number", |
502 | 16 | FT_UINT16, BASE_DEC, NULL, 0x0, |
503 | 16 | NULL, HFILL } |
504 | 16 | }, |
505 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_name, |
506 | 16 | { "Name", "fortinet_fgcp.hb.tlv.interface_inventory.name", |
507 | 16 | FT_STRINGZ, BASE_NONE, NULL, 0x0, |
508 | 16 | NULL, HFILL } |
509 | 16 | }, |
510 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_mac, |
511 | 16 | { "Mac", "fortinet_fgcp.hb.tlv.interface_inventory.mac", |
512 | 16 | FT_ETHER, BASE_NONE, NULL, 0x0, |
513 | 16 | NULL, HFILL } |
514 | 16 | }, |
515 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag, |
516 | 16 | { "Flag", "fortinet_fgcp.hb.tlv.interface_inventory.flag", |
517 | 16 | FT_UINT8, BASE_HEX, NULL, 0x0, |
518 | 16 | NULL, HFILL } |
519 | 16 | }, |
520 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_admin_status, |
521 | 16 | { "Admin Status", "fortinet_fgcp.hb.tlv.interface_inventory.flag.admin_status", |
522 | 16 | FT_BOOLEAN, 8, TFS(&tfs_up_down), 0x01, |
523 | 16 | NULL, HFILL } |
524 | 16 | }, |
525 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_operation_status, |
526 | 16 | { "Operation Status", "fortinet_fgcp.hb.tlv.interface_inventory.flag.operation_status", |
527 | 16 | FT_BOOLEAN, 8, TFS(&tfs_up_down), 0x02, |
528 | 16 | NULL, HFILL } |
529 | 16 | }, |
530 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_link_monitored, |
531 | 16 | { "Link Monitored", "fortinet_fgcp.hb.tlv.interface_inventory.flag.link_monitored", |
532 | 16 | FT_BOOLEAN, 8, NULL, 0x04, |
533 | 16 | NULL, HFILL } |
534 | 16 | }, |
535 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_ha_eligible, |
536 | 16 | { "HA Eligible", "fortinet_fgcp.hb.tlv.interface_inventory.flag.ha_eligbile", |
537 | 16 | FT_BOOLEAN, 8, NULL, 0x08, |
538 | 16 | NULL, HFILL } |
539 | 16 | }, |
540 | 16 | { &hf_fortinet_fgcp_hb_tlv_interface_inventory_flag_b74, |
541 | 16 | { "Reserved", "fortinet_fgcp.hb.tlv.interface_inventory.flag.b74", |
542 | 16 | FT_UINT8, BASE_HEX, NULL, 0xF0, |
543 | 16 | "Bit 7 to 4", HFILL } |
544 | 16 | }, |
545 | | /* |
546 | | { &hf_fortinet_fgcp_hb_unknown, |
547 | | { "Unknown", "fortinet_fgcp.hb.unknown", |
548 | | FT_BYTES, BASE_NONE, NULL, 0x0, |
549 | | "Always NULL ?", HFILL } |
550 | | }, |
551 | | */ |
552 | 16 | { &hf_fortinet_fgcp_hb_unknown_uint16, |
553 | 16 | { "Unknown", "fortinet_fgcp.hb.unknown.uint16", |
554 | 16 | FT_UINT16, BASE_DEC_HEX, NULL, 0x0, |
555 | 16 | NULL, HFILL } |
556 | 16 | }, |
557 | | |
558 | | /* Session */ |
559 | 16 | { &hf_fortinet_fgcp_session_magic, |
560 | 16 | { "Magic Number", "fortinet_fgcp.session.magic", |
561 | 16 | FT_UINT16, BASE_HEX_DEC, NULL, 0x0, |
562 | 16 | "Magic Number ?", HFILL } |
563 | 16 | }, |
564 | 16 | { &hf_fortinet_fgcp_session_type, |
565 | 16 | { "Type", "fortinet_fgcp.session.type", |
566 | 16 | FT_UINT16, BASE_HEX, NULL, 0x0, |
567 | 16 | NULL, HFILL } |
568 | 16 | }, |
569 | 16 | }; |
570 | | |
571 | | /* Setup protocol subtree array */ |
572 | 16 | static int *ett[] = { |
573 | 16 | &ett_fortinet_fgcp_hb, |
574 | 16 | &ett_fortinet_fgcp_hb_flag, |
575 | 16 | &ett_fortinet_fgcp_hb_tlv, |
576 | 16 | &ett_fortinet_fgcp_hb_tlv_interface, |
577 | 16 | &ett_fortinet_fgcp_hb_tlv_interface_flag, |
578 | 16 | &ett_fortinet_fgcp_session, |
579 | 16 | }; |
580 | | |
581 | | /* Register the protocol name and description */ |
582 | 16 | proto_fortinet_fgcp_hb = proto_register_protocol("FortiGate Cluster Protocol - HeartBeat", |
583 | 16 | "fortinet_fgcp_hb", "fortinet_fgcp_hb"); |
584 | | |
585 | 16 | proto_fortinet_fgcp_session = proto_register_protocol("FortiGate Cluster Protocol - Session", |
586 | 16 | "fortinet_fgcp_session", "fortinet_fgcp_session"); |
587 | | |
588 | | /* Required function calls to register the header fields and subtrees */ |
589 | 16 | proto_register_field_array(proto_fortinet_fgcp_hb, hf, array_length(hf)); |
590 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
591 | | |
592 | 16 | fortinet_fgcp_hb_handle = register_dissector("fortinet_fgcp_hb", dissect_fortinet_fgcp_hb, |
593 | 16 | proto_fortinet_fgcp_hb); |
594 | | |
595 | 16 | fortinet_fgcp_session_handle = register_dissector("fortinet_fgcp_session", dissect_fortinet_fgcp_session, |
596 | 16 | proto_fortinet_fgcp_session); |
597 | | |
598 | 16 | } |
599 | | |
600 | | |
601 | | void |
602 | | proto_reg_handoff_fortinet_fgcp(void) |
603 | 16 | { |
604 | 16 | dissector_add_uint("ethertype", ETHERTYPE_FORTINET_FGCP_HB, fortinet_fgcp_hb_handle); |
605 | 16 | dissector_add_uint("ethertype", ETHERTYPE_FORTINET_FGCP_SESSION, fortinet_fgcp_session_handle); |
606 | | |
607 | 16 | ip_handle = find_dissector_add_dependency("ip", proto_fortinet_fgcp_session); |
608 | 16 | } |
609 | | |
610 | | /* |
611 | | * Editor modelines - https://www.wireshark.org/tools/modelines.html |
612 | | * |
613 | | * Local variables: |
614 | | * c-basic-offset: 4 |
615 | | * tab-width: 8 |
616 | | * indent-tabs-mode: nil |
617 | | * End: |
618 | | * |
619 | | * vi: set shiftwidth=4 tabstop=8 expandtab: |
620 | | * :indentSize=4:tabSize=8:noTabs=true: |
621 | | */ |