Wireshark mailing list archives

Re: Sniffing LACP traffic with wireshark


From: Guy Harris <guy () alum mit edu>
Date: Fri, 30 May 2014 16:01:23 -0700


On May 30, 2014, at 3:12 PM, Guy Harris <guy () alum mit edu> wrote:

"-d" doesn't do filtering, it does "Decode As...".  You don't need "Decode As..." or "-d" to get Wireshark/TShark to 
recognize traffic with an ethertype of 0x8809 as "slow protocol" traffic or to get "slow protocol" traffic with a 
subtype of  0 to be recognized as LACP traffic.

Sorry, that's subtype 1, not 0, for LACP.

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: