Wireshark mailing list archives

Re: Does it make any sense to supply Radiotap + 802.11 headers for packets captured on wireless adapter for managed mode?


From: Guy Harris <guy () alum mit edu>
Date: Tue, 19 Apr 2016 09:34:10 -0700

On Apr 19, 2016, at 7:09 AM, Yang Luo <hsluoyb () gmail com> wrote:

Someone told me that:
      • could you please automatically provide Ethernet pseudo-headers rather than Radiotap etc. when the WLAN NIC is 
switched to "managed" (STA) mode? The point is that Wireshark doesn't dissect frames whose 802.11 header indicates 
some Data subtypes (probably encrypted ones) although the actual payload has been decrypted by the NIC. So you can 
see the plaintext contents in the hex dump but the dissection says just "Data".

So it seems that Wireshark doesn't quite support option 3)?

What's probably happening is that the Protected bit is set but the packet contents are decrypted.

One of the "Yes" options for "Ignore the Protection bit" preference might make that work.
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: