Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] capture filter of PPP LCP

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Mon, 24 Dec 2007 17:03:55 +0100
Hi,

That is a display filter syntax you're writing. Consult man tcpdump for capture file syntax. There you will find there's no real way to filter PPP LCP this way.

Thanx,
Jaap

cw@xxxxxxxxxx wrote:
Hello everyone!
    I'd like to write a capture filter, to capture only PPP LCP packets, I
use ppp[0:2] = 0xc021, the first two bytes "0xc021" of PPP header means
Link Control Protocol(LCP), this capture filter should work, but it
captures nothing, why?
    Any suggestion is welcome.

Best Regards
cwflying