PRES Users Context List in Wireshark

Wireshark uses tables to show data and statistics to the user. The summarized data displayed in tables reduce the complexity of the information and make it easy for the user to analyze. For managing and editing these tables in Wireshark, the User Table editor is used. Wireshark PRES Users Context List is also a user table to map a presentation context identifier to a given object identifier when the capture does not contain a PRES package with a presentation context definition list for the conversation.

Steps To Open PRES Users Context List:

To open Wireshark’s PRES Users Context List, follow the steps below : 

  • Start the Wireshark by selecting the network we want to analyze or opening any previously saved captured file.
  • Now go into the Wireshark and click on the Edit → Preferences menu or toolbar item.

 

  • This will open Wireshark’s “Preferences” dialogue box.

 

  • On the “Preferences” dialogue box, click on the drop-down option “Protocols”. All the available protocols that Wireshark supports are listed down below.
  • Now scroll down and search for the “PRES Users Context List”.

 

  • Now just click on the “Edit” option. This will bring up Wireshark’s PRES Users Context List table.

 

This users’ table has two fields :

  • Context ID: It represents the presentation context identifier for which this association is valid.
  • Syntax Name OID: The object identifier representing the abstract syntax name, which defines the protocol that is carried over this association.

This user table contains the following controls :

  1. “+”:  For adding a new entry in the user table.
  2. “—”:  For removing any existing entry from the user table
  3. “ ∧ “:  For moving up in the entries.
  4. “ ∨ “:  For down in the entries.
  5. Copy: For creating a duplicate of the selected entry.
  6. Clear: For clearing all the existing entries from the user table.