Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: Re: [Ethereal-dev] WTAP_ENCAP_FRELAY

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Thu, 1 Jul 2004 01:33:21 -0700
On Tue, Jun 22, 2004 at 12:38:42PM +0200, Marc Carbones wrote:
> I'm trying to open Sniffer Pro cap files captured with a Wan Book, the
> only thing I can see are the Frame Relay headers of the packets that the
> Wan Book captures.
>  
> I've been searching on the Internet and see documents about
> WTAP_ENCAP_FRELAY and it seems this is a plugin or something else to
> succesfully read the IP packets inside the FR header.

Have you gotten Sniffer Pro to successfully read the IP packets?

If so, what does it show for the Frame Relay headers?  I.e., is it
treating the address field as an address containing only one octet? 
Q.922 says "The address field shall consist of at least two octets",
meaning that the low-order bit of the first byte of the address field
must be zero, but that byte is 0x0f in all the packets, as noted by Tom
Nisbet.

If not, then the problem is that they're not valid Frame Relay
packets according to Q.922....