ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] PPI header capture through rpcap not working

From: "Gianluca Varenni" <gianluca.varenni@xxxxxxxxxxxx>
Date: Tue, 8 Jul 2008 08:45:44 -0700
It's possible that the madwifi-ng drivers do not support the PPI encapsulation. I would probably check with the madwifi-ng folks about that. Can you capture packets with PPI encapsulation on the linux machine locally (e.g. with tcpdump)?

Have a nice day
GV



----- Original Message ----- From: "Amit Vartak" <amitv20@xxxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Sent: Monday, July 07, 2008 10:49 AM
Subject: [Wireshark-users] PPI header capture through rpcap not working


Hello,

I am trying to capture IEEE 802.11n packets with PPI headers with the help of rpcap (remote capture) method. I have installed wireshark 1.0.1 on windows XP (this is remote desktop) and using madwifi-ng custom drivers for capturing 802.11n packets on a linux box.

When i start remote capture, I get an error something like "192" can not be a part of capture filter. Here the link-type is actually 192 (this is link type in standard pcap file header) When i set link type as PRISM header (i.e. == 119 ) the capture works very well, and wireshark recognizes that packets contain PRISM header and decodes properly. When i change the link type to that of PPI header, this problem is coming.

When I open some PPI header file through the same wireshark version, i am able to see packets header properly but only while rpcap remote capture, i am facing this kindda problem.

Does anyone have faced similar problem or have any clue why it is happening like this?

-Amit





_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users