Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: RE: [Ethereal-dev] help needed about sniffing on WLAN

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Martijn Schipper" <martijn.schipper@xxxxxxxxxxxx>
Date: Wed, 29 Sep 2004 19:33:39 +0200
No, I mean all 802.11 frames are encapsulated in 802.3 frames by our firmware. We use this to pass these frames up in Windows with winpcap (or any other OS).

-----Oorspronkelijk bericht-----
Van: ethereal-dev-bounces@xxxxxxxxxxxx
[mailto:ethereal-dev-bounces@xxxxxxxxxxxx]Namens Guy Harris
Verzonden: woensdag 29 september 2004 19:14
Aan: Ethereal development
Onderwerp: Re: [Ethereal-dev] help needed about sniffing on WLAN


Martijn Schipper wrote:

> What kind of Prism card are you using? If you have an 11g/11a card then > that is correct. In promiscuous mode we encapsulate the 802.11 frame in > an 802.3 frame with an additional radio header.

...and presumably the only packets that are captured are data packets, 
so there's not much information lost by using the fake 802.3 headers.

If he wants to see more than just data packets, such as management 
packets, he'll have to capture in monitor mode; the Ethereal FAQ entry I 
sent him earlier discusses how to do so in Linux.

_______________________________________________
Ethereal-dev mailing list
Ethereal-dev@xxxxxxxxxxxx
http://www.ethereal.com/mailman/listinfo/ethereal-dev


******************Legal Disclaimer**************************
"This email may contain confidential and privileged material for the sole use of the intended recipient.  Any unauthorized review, use or distribution by others is strictly prohibited.  If you have received the message in error, please advise the sender by reply email and delete the message. Thank you."
****************************************************************