Document toolboxDocument toolbox

TAP Curious FAQ

For a synchronized distributed measurement at several locations in a network, we would like to use some TAP Curious. Is there a possibility to synchronize them via the External IO ports, e.g. by applying a common second pulse to the inputs, which is recorded in the capture and to which the time stamps can be synchronized in the data post-processing?

After researching the manual, I can tell you that the digital input can only be linked to filter parameters.

This means that it is possible to consider the state of the digital input when you create a packet filter.

For example, you can define that data is only output on the uplink port if:

  • High level is present at the input

  • Certain other filter criteria apply

I am having a problem setting the IP address to work on our network when accessing the web interface.

It is unfortunately a known issue.

Are there any plans to release the TAP Curious Wireshark plugin software open source?

No

How can I use the digital output? Is there an example of this?

The following example activates the digital output for three seconds when Modbus TCP telegrams are received. You can import it via the HTTP interface of the uplink port.

Apparently large frames are not displayed in Wireshark. What can I do?

Please refer to the user manual chapter 10 for the problem: "Wireshark does not display large packets."

The TAP appends 20 bytes of additional information to the packets. If large packets with more than 1480 bytes of user data are transmitted, the maximum packet length of 1500 bytes (1518 bytes including Ethernet header and CRC) is exceeded. Ethernet header and CRC) is exceeded and and the packet is normally rejected by the Ethernet card in the computer running Wireshark.

This can be avoided by enabling 'Jumbo Packets' in the driver.

I want to use the TAP Curious together with Sercos III and have problems. What can I do?

Unfortunately the TAP Curious is incompatible under Sercos III, please contact our sales department for a quote.

Unfortunately in Wireshark I don't see the data now when I load a recording without TAP connected from the file system. Do I have to explicitly specify that the data of the TAP is also recorded?

We had observed such phenomena in the past. What happened was that the TAP plugin had terminated silently. It may be that the TAP plugin is out of date. You can find the latest plugin here:

https://www.kunbus.com/downloads.html#analysistools

Wireshark-Plugin

In Wireshark the protocol was enabled. But I can't find any extra entries of the TAP Curious while "listening" on the Ethernet interface. What do I have to do?

The TAP Wireshark plugin tries to decode a 20 byte footer. This is appended to the data stream at the uplink port. No setting is necessary for this. The manual points out that in certain circumstances with large packets this footer is not output. See here:

Are special settings required for fieldbus XY? The TAP Curious reports faulty telegrams, which I do not receive with a TAP from another manufacturer.

No special settings are required. The TAP Curious is by design passive on the Ethernet network which differentiates the device from other devices when sampling data.

Please refer to the following chapters in the TAP Curious manual:

  • 10 Errors and problems

  • 10.1 Decoupling non-compliant Ethernet interfaces

Where can I download the latest Wireshark TAP plugin?


Have a look here:

Where can I find the TAP documentation?

Rigth here:

Since the product is discontinued, the Wireshark plugins will not be developed further.

I have a TAP2000. Where can I find the latest TAP Wireshark plugin?

Unfortunately, the TAP2000 product has been discontinued. Therefore the plugins will not be updated anymore. Please contact our sales team for a quote for a TAP Curious.

I want to use the precise TAP Curious Timestamp in Wireshark but it is only possible to show in hexadecimal format. What can I do?

The TAP Wireshark Plugin will apply in the "Time" column by the highly-precise timestamp from the TAP CURIOUS instead of the timestamp from the operating system.

You just have to install and activate the TAP Curious Wireshark plugin.

In which directory do I have to copy the TAP Wireshark plugin?

An example for Wireshark 3.4

64 Bit

C:\Program Files\Wireshark\plugins\3.4\epan

32 Bit

c:\Program Files (x86)\Wireshark\plugins\3.4\epan

I cannot find old versions of Wireshark. Where do I get older versions of Wireshark?

Have a look at these URLs

Why is there a big text file in the Wireshark folder?

This is a known bug of the TAP Wireshark plugin which has been fixed. Please update to the latest TAP plugin. Maybe you also have to update Wireshark to the version that matches the plugin. It might be slightly behind the latest release.

Is there a way to reset all filter settings to the defaults?

Yes, you have to update the WebServer files. Have a look at this document:

I cannot open the web interface. What can I do?

Please check your Ethernet IP configuration. You have to use the network 192.168.0.0/24, i.e. 192.168.0.11 with subnet 255.255.255.0 to access the web interface at 192.168.0.10.

 

I cannot capture frames. What can I do?

Please check the speed of the uplink Ethernet interface. You have to use a Gigabit network interface at the uplink port.

Some Con activity LEDs are lighting red. What does this mean?

The LED status indicates that the TAP filters have been triggered. Please reset the filters using the web interface at http://192.168.0.10

Upload the contents of the file.

Wireshark crashes when the TAP plugin is installed. What can I do?

Verify if the Wireshark version matches the latest TAP plugin.

It is not possible to enable the TAP protocol in the Wireshark settings. What can I do?

The menu structure has changed in Wireshark. You can use [ Ctrl ] + [ Shift ] + [ E ] “Enabled Protocols” or use the menu Analyze → Enabled Protocols…

(in older versions you may have to search for "tap" instead of "kbtap")

 

Wireshark starts and displays the following error. What can I do?

Have a look at your plugins subfolder and search for duplicate plugins and delete them.

Is it possible to switch the Time format in Wireshark?

Yes, it is possible.

Right click on the column and select settings or similar.

Add a column and set the values accordingly

 

Why is the TAP plugin not loaded in Wireshark?

This is a known bug. Please update your plugin and your Wireshark version. Alternatively try to run Wireshark as administrator.

Can I use PoE Power over Ethernet with the TAP?

No, unfortunately the TAP Curious cannot be used in a PoE environment. This can destroy the device.

The Overflow LED is lighting red what does this mean?

The TAP is on 100 MBit/s mode - use a GBit ethernet connection.