Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Fake MAC addresses in text2pcap and "Import from hex dump"

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 11 Apr 2016 17:04:05 -0700
When synthesizing an Ethernet header, text2pcap uses 0a:02:02:02:02:02 as the destination address and 0a:01:01:01:01:01 as the source address, while "Import from hex dump" uses 20:52:45:43:56:00 as the destination and 20:53:45:4E:44:00 as the source.

Is there some reason why they're different?

If not, which of them *should* both be using?