Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Fake MAC addresses in text2pcap and "Import from hex dump"

From: Anders Broman <anders.broman@xxxxxxxxxxxx>
Date: Tue, 12 Apr 2016 08:47:23 +0000

-----Original Message-----
From: wireshark-dev-bounces@xxxxxxxxxxxxx [mailto:wireshark-dev-bounces@xxxxxxxxxxxxx] On Behalf Of Guy Harris
Sent: den 12 april 2016 02:04
To: Developer support list for Wireshark
Subject: [Wireshark-dev] Fake MAC addresses in text2pcap and "Import from hex dump"

When synthesizing an Ethernet header, text2pcap uses 0a:02:02:02:02:02 as the destination address and 0a:01:01:01:01:01 as the source address, while "Import from hex dump" uses 20:52:45:43:56:00 as the destination and 20:53:45:4E:44:00 as the source.

Is there some reason why they're different?

If not, which of them *should* both be using?
Even if  R E C V and S E N D is clever I think I prefer the other one which makes it clearer that it's a fake MAC.

Regards
Anders
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev@xxxxxxxxxxxxx>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request@xxxxxxxxxxxxx?subject=unsubscribe