Wireshark-bugs: [Wireshark-bugs] [Bug 12081] Add 'Decode as' support for SLL Type field
Date: Thu, 04 Feb 2016 22:16:57 +0000

Comment # 8 on bug 12081 from
> Any protocol type <= 1536 is a SLL Type protocol

I see. This is not mentioned in the SLL format description (via
https://wiki.wireshark.org/Development/LibpcapFileFormat ->
http://www.tcpdump.org/linktypes.html ->
http://www.tcpdump.org/linktypes/LINKTYPE_LINUX_SLL.html ). But this can also
be due to my lack of understanding of Ethernet protocol types.

> Note that EAPOL does not register itself as a valid protocol for Linux SLL
> protocol type. So even with sll.ltype added to 'Decode As', you cannot select
> it.

Is there a better way to hand some raw application layer data without the
network layer etc. to Wireshark and have it analyze it?


You are receiving this mail because:
  • You are watching all bug changes.