Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Strange decoding?

From: Vincent CATROS <vincent.catros@xxxxxxxxxxx>
Date: Wed, 25 Jan 2012 11:13:54 +0100
Hello,

I have a faulty equipement sending IPv6 packets with ethertype 0x0800 (IPv4).
Nevertheless Wireshark decodes it as IPv6. (check packet #6 of the joined file).

It seems strange to me, I thought Wireshark uses ethertype for decoding, or least selecting the disector, but it does not seems to be the case. And even if Wireshark uses an other method I would have like it to warn me.

Could someone explain to me why this behaviour?

Regards.
Vincent

Une messagerie gratuite, garantie à vie et des services en plus, ça vous tente ?
Je crée ma boîte mail www.laposte.net

Attachment: capture_PC_pppoe_google_ko_2012-01-23_1-filtered.pcap
Description: Binary data