Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: [Ethereal-dev] Broken WellFleet packet-types/DLT types ...

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Richard Sharpe <rsharpe@xxxxxxxxxxxxxxxxx>
Date: Thu, 19 Dec 2002 13:15:06 -0800 (PST)
Hmmm,

It seems that the WellFleet that we have problems with uses/used a 
modified PPP over Sync header with 0x0703 as the first two bytes.

The first 7 bytes of the capture file contained the words TRSNIFF, which 
would seem to be a way to detect that it is a different capture type and 
allocate a DLT value to it, rather than LAPB?

Does anyone have any quick hints on doing this?
 
Regards
-----
Richard Sharpe, rsharpe[at]ns.aus.com, rsharpe[at]samba.org, 
sharpe[at]ethereal.com, http://www.richardsharpe.com