

Upon viewing my captures I was able to see dissections of AVPs with vendorID=0x118b and registered type codes. I don't remember which version had this working correctly, but it did. Their parsing has been broken in Wireshark 1.10.6 in Ubuntu. The protocol is an extension of L2TP and so uses a bunch of VendorID-scoped AVP extensions. Mostly, it is DEPI control plane see the Downstream External PHY Interface specification by CableLabs.

pcapng captures of a specific type of L2TP traffic.
