Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Does it make any sense to supply Radiotap + 802.11 headers f

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 19 Apr 2016 09:34:10 -0700
On Apr 19, 2016, at 7:09 AM, Yang Luo <hsluoyb@xxxxxxxxx> wrote:

> Someone told me that:
> 	• could you please automatically provide Ethernet pseudo-headers rather than Radiotap etc. when the WLAN NIC is switched to "managed" (STA) mode? The point is that Wireshark doesn't dissect frames whose 802.11 header indicates some Data subtypes (probably encrypted ones) although the actual payload has been decrypted by the NIC. So you can see the plaintext contents in the hex dump but the dissection says just "Data".
> 
> So it seems that Wireshark doesn't quite support option 3)?

What's probably happening is that the Protected bit is set but the packet contents are decrypted.

One of the "Yes" options for "Ignore the Protection bit" preference might make that work.