Wireshark-dev: Re: [Wireshark-dev] writing non-Ethernet pcapng files
From: Aaron Turner <synfinatic@xxxxxxxxx>
Date: Thu, 21 May 2009 13:39:58 -0700
On Thu, May 21, 2009 at 1:06 PM, Michael Tüxen
<Michael.Tuexen@xxxxxxxxxxxxxxxxx> wrote:
> Hi Aaron,
>
> I see what you mean. I'm using pcapio.[ch] in dumpcap,
> so I'm using WTAP_ENCAP_PER_PACKET...
>
> Can you file a bug report at https://bugs.wireshark.org/bugzilla/
> such that it does not get forgotten. Please describe
> what you want to get working (possibly providing the
> input file). Then it does not get lost.
>
> I will look at it after finishing the capturing support,
> if no one else takes the issue earlier.

Well looks like it was more work then I thought... converting from
pcap to pcapng looses the ecapsulation type for some reason (at least
with my HDLC test).  I'm going to see if I can dig around and figure
out what's going on.

-- 
Aaron Turner
http://synfin.net/
http://tcpreplay.synfin.net/ - Pcap editing and replay tools for Unix & Windows
Those who would give up essential Liberty, to purchase a little temporary
Safety, deserve neither Liberty nor Safety.
    -- Benjamin Franklin