<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/126510/sniffing-ble-ndfu</link><description>i am performing DFU process b/w nrf54l15 and nrf connect mobile_app ( Android ) and i am sniffing the it using nrf54840 soc and the bord is nrf21540dk in Wireshark i know DFU process uses pairing for security, mtu exchange then firmware is divided into</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 16 Jan 2026 11:32:14 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/126510/sniffing-ble-ndfu" /><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558877?ContentTypeID=1</link><pubDate>Fri, 16 Jan 2026 11:32:14 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:f1f2a692-496d-42e9-b8eb-1b5a677144d7</guid><dc:creator>Hieu</dc:creator><description>&lt;p&gt;Hi Sumit,&lt;/p&gt;
&lt;p&gt;I am glad you are able to resolve your issue. These LTK are unique per connections, but maybe it&amp;#39;s still a good idea not to share them in a public space.&lt;/p&gt;
&lt;p&gt;Then if everything is working fine, please feel free to close this ticket at your convenience.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558873?ContentTypeID=1</link><pubDate>Fri, 16 Jan 2026 10:56:56 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e3fb9dd6-1d76-4e10-b42b-6b8804a9f47e</guid><dc:creator>Sumit Paropkari</dc:creator><description>&lt;div&gt;&lt;span style="font-family:arial, helvetica, sans-serif;"&gt;&lt;span style="color:#000000;"&gt;Hello Hieu,&lt;br /&gt;&lt;br /&gt;Thank you for your support. We are successfully&amp;nbsp;able to capture DFU Process in the Wireshark. The only Catch is that we have to disconnect and reconnect until we see&lt;/span&gt;&lt;b&gt;&lt;span style="color:#6aa84f;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="color:#6aa84f;font-size:large;"&gt;Flag&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="color:#6aa84f;font-size:large;"&gt;Encrypted = YES&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;Then we have to start actual DFU.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;This is the&amp;nbsp;&lt;/span&gt;SC LTK: 0x43bcedd0b9c34906ccd7ce2cf13abed3 at that time.&amp;nbsp;&lt;span&gt;successfully&amp;nbsp;&lt;/span&gt;&lt;span&gt;capture&lt;/span&gt;&lt;span&gt;&amp;nbsp;Wireshark log you can see that with this link :&amp;nbsp;&lt;/span&gt;&lt;a href="https://drive.google.com/drive/folders/1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w?usp=sharing"&gt;https://drive.google.com/drive/folders/1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w?usp=sharing&lt;/a&gt;.&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558838?ContentTypeID=1</link><pubDate>Thu, 15 Jan 2026 21:50:22 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:ce1a8d3b-618f-4c5e-ac24-854feffbbea2</guid><dc:creator>Hieu</dc:creator><description>&lt;p&gt;Hello Sumit,&lt;/p&gt;
&lt;p&gt;You are probably missing some steps. Please refer to the instructions here, in particular, follow step 8 through 10 closely, including the disconnecting and reconnecting.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://academy.nordicsemi.com/courses/bluetooth-low-energy-fundamentals/lessons/lesson-6-bluetooth-le-sniffer/topic/blefund-lesson-6-exercise-3/"&gt;Exercise 3 - Follow and decrypt a paired connection - Nordic Developer Academy&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558710?ContentTypeID=1</link><pubDate>Wed, 14 Jan 2026 13:22:54 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e40b0d0b-b0e3-44ef-b61f-6c4f49aa2c4e</guid><dc:creator>Sumit Paropkari</dc:creator><description>&lt;p&gt;Hello Hieu,&lt;/p&gt;
&lt;p&gt;yes, you are correct but i am currently able to capture sniff&amp;nbsp; BLE ADV and connection initiation from Target device and all near by devices in the Wireshark it means Sniffer is working good and also also capturing data in wireshark.&lt;br /&gt;&lt;br /&gt;My problem is that when i am try to capture DFU process of a targeted device (mac_id : &lt;span&gt;e3:4d:26:1c:52:c2&lt;/span&gt; ) that is not captured. in the Wireshark due to encryption and no smp packet is captured.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;SC LTK: 0x40370a1753f59af41f0f267079363216&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;you can also verified by Attachment :&amp;nbsp;Contain the &lt;span&gt;Wireshark-log and target device log&lt;br /&gt;&lt;a href="https://drive.google.com/drive/folders/1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w?usp=sharing"&gt;drive.google.com/.../1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558690?ContentTypeID=1</link><pubDate>Wed, 14 Jan 2026 11:56:06 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:89cbbce3-bca7-41ed-968c-073b9b6c73c6</guid><dc:creator>Hieu</dc:creator><description>&lt;p&gt;Hello Sumit,&lt;/p&gt;
&lt;p&gt;On the nRF21540 DK, the nRF52840 is connected to a nRF21540 FEM always. The firmware in&amp;nbsp;&lt;span&gt;sniffer_nrf52840dk_nrf52840_4.1.1.hex has no FEM control, so the FEM is most likely in power down all the time and not working. What happens then is that&amp;nbsp;the setup will have&amp;nbsp;very very bad radio performance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I expect this is the main cause of your issue. &lt;a href="https://docs.nordicsemi.com/bundle/nrfutil/page/nrfutil-ble-sniffer/guides/requirements.html"&gt;Please&amp;nbsp;use another DK or Dongle that is supported by the sniffer&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Hieu&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing BLE nDFU</title><link>https://devzone.nordicsemi.com/thread/558664?ContentTypeID=1</link><pubDate>Wed, 14 Jan 2026 08:22:51 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1d27c436-e6a1-48ee-a44a-0051177a0d0b</guid><dc:creator>Sumit Paropkari</dc:creator><description>&lt;p&gt;Attachment link : :&lt;a href="https://drive.google.com/drive/folders/1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w?usp=sharing"&gt;drive.google.com/.../1PyMsgcf5cmHa2-pMTZ5Wy6GZcBrOr55w&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>