Wireshark mailing list archives
Re: Sniffing LACP traffic with wireshark
From: Guy Harris <guy () alum mit edu>
Date: Fri, 30 May 2014 16:01:23 -0700
On May 30, 2014, at 3:12 PM, Guy Harris <guy () alum mit edu> wrote:
"-d" doesn't do filtering, it does "Decode As...". You don't need "Decode As..." or "-d" to get Wireshark/TShark to recognize traffic with an ethertype of 0x8809 as "slow protocol" traffic or to get "slow protocol" traffic with a subtype of 0 to be recognized as LACP traffic.
Sorry, that's subtype 1, not 0, for LACP. ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- Sniffing LACP traffic with wireshark Kevin Wilson (May 30)
- Re: Sniffing LACP traffic with wireshark Jaap Keuter (May 30)
- Re: Sniffing LACP traffic with wireshark Guy Harris (May 30)
- Re: Sniffing LACP traffic with wireshark Guy Harris (May 30)