# DO NOT EDIT THIS FILE! It was created by Wireshark @Attn@ tcp.analysis.flags || tcp.checksum_bad || udp.checksum_bad || ip.fragment.error || ip.fragment.overlap.conflict || ip.fragment.overlap@[52428,17476,17476][65535,65535,65535] @NW Change@(hsrp.state != 8 && hsrp.state !=16) || stp.type == 0x80 || ospf.msg != 1@[34952,34952,34952][65535,65535,0] @NW Traf@stp.protocol || cdp || hsrp || vrrp || ospf || bgp || eigrp || rip || gvrp || rtmp || igmp || eth.addr == 01:00:0c:cc:cc:cc@[34952,34952,34952][0,0,0] @Core Srvcs@arp || ntp || dns || udp.port == 67 || udp.port == 68@[34952,34952,43690][0,0,0] @Multicast@ip.dst > 224.0.0.0@[39321,48059,39321][0,0,0] @ICMP Err@icmp.type range 3 5 || icmp.type eq 11@[56540,52017,56540][65535,0,0] @ICMP@icmp@[56540,51914,56540][0,0,0] @RST@tcp.flags & 0x04@[61717,47055,24609][0,0,0] @SYN@tcp.flags & 0x02@[30583,65535,30583][607,3474,607] @FIN@tcp.flags & 0x01@[65535,34952,34952][0,0,0] @HTTP@http@[43734,43734,56797][0,0,0] @NetBIOS@netbios || nbns || smb || srvloc || srvsvc || nbss@[36700,36700,61166][0,0,0] @TCP@tcp@[53739,53739,65535][0,0,0] @UDP@udp@[60948,60948,65535][0,0,0]