ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-users: Re: [Ethereal-users] New User - How do I cpature/save Cisco Debugs For Analysis

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <guy@xxxxxxxxxx>
Date: Thu, 20 Jun 2002 15:18:38 -0700
On Fri, Jun 21, 2002 at 12:09:25AM +0200, M.C. van den Bovenkamp wrote:
> If either of the interfaces is not Ethernet, that's not the case, anf 
> Funky Stuff happens when the output of the script gets fed to text2pcap 
> :-). But perhaps something could be reverse-enineered about the 
> resulting hexdump (fake addresses and using only select bits of it?). I 
> haven't looked at it that deeply (yet?).

Well, if the interface was a Token Ring interface, for example, perhaps
Correct Stuff would happen if you ran text2pcap with "-l 6" to tell
text2pcap to mark the output file as a Token Ring capture rather than an
Ethernet capture.

There may be other interface types for which that can be made to work
(e.g., FDDI, with "-l 10"); WAN interfaces might be trickier, as I don't
know whether the header would be a PPP header or would include
WAN-type-specific headers.