Wireshark mailing list archives

Re: where is WTAP_ENCAP type 80 (K12) in Import menue/or why is it not there?


From: Guy Harris <guy () alum mit edu>
Date: Mon, 4 Mar 2013 23:49:48 -0800


On Mar 4, 2013, at 10:24 PM, Ariel Burbaickij <ariel.burbaickij () gmail com> wrote:

I have several captures. One of them is definitely in rf5 format,

...which means it definitely is given the WTAP_ENCAP_ value of WTAP_ENCAP_K12, not WTAP_ENCAP_MTP2.

another one is definitely in pcap format.

...which means it definitely is *not* given the WTAP_ENCAP_ value of WTAP_ENCAP_K12, although it could be given the 
WTAP_ENCAP_ value of WTAP_ENCAP_MTP2.

What I meant is  that from looking  at supported DLT_TYPEs and then WTAP_ENCAP (sets of supported encapsulations are 
different) it appeared to me that development of wireshark and tcereplay happens totally independent from each other 
-- previously I thought/hoped that it happens in more coordinated way.

Nope.  That would be like hoping that the development of Wireshark and snoop, or the development of Wireshark and 
tcpdump, or the development of Wireshark and any *other* libpcap-based application, happened in a more coordinated way.

Wireshark's development deliberately does *not* limit itself to what libpcap can read.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: