tcpdump mailing list archives

Re: Problem with generation of Pcap traces for


From: Aaron Turner <synfinatic () gmail com>
Date: Sat, 16 May 2009 10:33:11 -0700

On Sat, May 16, 2009 at 10:12 AM, Guy Harris <guy () alum mit edu> wrote:

On May 16, 2009, at 3:18 AM, Johan Mazel wrote:

Does this restriction means that I can't aggregate trace of different
version of Ethernet (eg.: 802.3 and 802.11) ?

(802.11 isn't a version of Ethernet.)

If your 802.11 device supplies "fake Ethernet" headers, you can aggregate
its packets with Ethernet packets; if it supplies 802.11 headers, with or
without radio headers, you can't.

Actually there is a way to do it- convert your 802.11 frames to 802.3
before writing.   You can do that yourself or steal my tcpedit code
from tcpreplay.  One of these days I'll make it a standalone library,
but haven't found the time.

-- 
Aaron Turner
http://synfin.net/
http://tcpreplay.synfin.net/ - Pcap editing and replay tools for Unix & Windows
Those who would give up essential Liberty, to purchase a little temporary
Safety, deserve neither Liberty nor Safety.
    -- Benjamin Franklin
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: