Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] PPI header capture through rpcap not working

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Gianluca Varenni" <gianluca.varenni@xxxxxxxxxxxx>
Date: Tue, 8 Jul 2008 08:45:44 -0700

It's possible that the madwifi-ng drivers do not support the PPI encapsulation. I would probably check with the madwifi-ng folks about that. Can you capture packets with PPI encapsulation on the linux machine locally (e.g. with tcpdump)?

Have a nice day
GV



----- Original Message ----- From: "Amit Vartak" <amitv20@xxxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Sent: Monday, July 07, 2008 10:49 AM
Subject: [Wireshark-users] PPI header capture through rpcap not working


Hello,

I am trying to capture IEEE 802.11n packets with PPI headers with the help of rpcap (remote capture) method. I have installed wireshark 1.0.1 on windows XP (this is remote desktop) and using madwifi-ng custom drivers for capturing 802.11n packets on a linux box.

When i start remote capture, I get an error something like "192" can not be a part of capture filter. Here the link-type is actually 192 (this is link type in standard pcap file header) When i set link type as PRISM header (i.e. == 119 ) the capture works very well, and wireshark recognizes that packets contain PRISM header and decodes properly. When i change the link type to that of PPI header, this problem is coming.

When I open some PPI header file through the same wireshark version, i am able to see packets header properly but only while rpcap remote capture, i am facing this kindda problem.

Does anyone have faced similar problem or have any clue why it is happening like this?

-Amit





_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users


  • References:
    • [Wireshark-users] PPI header capture through rpcap not working
      • From: Amit Vartak
  • Prev by Date: [Wireshark-users] Does Wireshark modify the Ethernet Interface in ANY way while capturing?
  • Next by Date: Re: [Wireshark-users] MTP2 HSL Capture filtering
  • Previous by thread: [Wireshark-users] PPI header capture through rpcap not working
  • Next by thread: Re: [Wireshark-users] how to print time with epoch formation by tshark
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation