Display Filter Reference: Logical-Link Control

Protocol field name: llc

Versions: 1.0.0 to 2.6.1

Back to Display Filter Reference

Field name Description Type Versions
llc.bluetooth_pid PID Unsigned integer, 2 bytes 1.10.0 to 2.6.1
llc.cimetrics_pid PID Unsigned integer, 2 bytes 1.2.0 to 2.6.1
llc.cisco_pid PID Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control Control Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control.f Final Boolean 1.0.0 to 2.6.1
llc.control.ftype Frame type Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control.n_r N(R) Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control.n_s N(S) Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control.p Poll Boolean 1.0.0 to 2.6.1
llc.control.s_ftype Supervisory frame type Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.control.u_modifier_cmd Command Unsigned integer, 1 byte 1.0.0 to 2.6.1
llc.control.u_modifier_resp Response Unsigned integer, 1 byte 1.0.0 to 2.6.1
llc.dsap DSAP Unsigned integer, 1 byte 1.0.0 to 2.6.1
llc.dsap.ig IG Bit Boolean 1.0.0 to 2.6.1
llc.dsap.sap SAP Unsigned integer, 1 byte 2.0.0 to 2.6.1
llc.extreme_pid PID Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.force10_pid PID Unsigned integer, 2 bytes 1.2.0 to 2.6.1
llc.foundry_pid PID Unsigned integer, 2 bytes 1.10.0 to 2.6.1
llc.hpteam_pid PID Unsigned integer, 2 bytes 1.4.0 to 2.6.1
llc.iana_pid PID Unsigned integer, 2 bytes 1.2.0 to 2.6.1
llc.nortel_pid PID Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.oui Organization Code Unsigned integer, 3 bytes 1.0.0 to 2.6.1
llc.pid Protocol ID Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.ssap SSAP Unsigned integer, 1 byte 1.0.0 to 2.6.1
llc.ssap.cr CR Bit Boolean 1.0.0 to 2.6.1
llc.ssap.sap SAP Unsigned integer, 1 byte 2.0.0 to 2.6.1
llc.type Type Unsigned integer, 2 bytes 1.0.0 to 2.6.1
llc.wlccp_pid PID Unsigned integer, 2 bytes 1.0.0 to 2.6.1
mausb.pid PID Unsigned integer, 2 bytes 1.12.0 to 2.6.1
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More