Thanks for the response and good call. While I'm having trouble
compiling Wireshark (WS) on the Linux box, I was able to download (with
the lan folks permission) and install WS on my Windows workstation and
take a look at the capture file. You are correct; the packets are not
flagged as malformed on the latest WS release. I think the lan folks
will now replace Ethereal with WS on their sniffer.
Note that "Malformed packet" can have at least two reasons: .......
"CONFIDENTIALITY NOTICE: This communication, including any attachments, may contain confidential information and is intended only for the individual or entity to whom it is addressed. Any review, dissemination, or copying of this communication by anyone other than the intended recipient is strictly prohibited. If you are not the intended recipient, please contact the sender by reply email and delete and destroy all copies of the original message."