Date: Sat, 29 May 2010 01:45:09 -0700 (PDT)

--- Comment #1 from Jaap Keuter <[email protected]> 2010-05-29 10:45:04 CEST ---
(In reply to comment #0)
> Currently Wirshark users can write their own dissectors for any protocol in
> form of DLL plugins.
> Sometimes it is useful and necessary to write a plugin for a specific data link
> type (encapsulation) rather than a protocol. A user may want to modify the
> current dissector for a data link type from scratch.

That's a layer 2 thing

> So I think adding this feature to Wireshark will be useful.
> (e.g. I want to dissect the ethernet packets with a specific (proprietary)
> ether-type in a completely different manner than current ethernet dissector. So
> I need to modify current ethernet data link type code.)

That's a layer 3 thing

Please note that Wireshark runs dissection on WTAP types. That's an aggregation
of all known capture file types encapsulations, see wiretap/wtap.[ch].

