Wireshark-users: [Wireshark-users] Fake Ethernet II header with 802.11 protocol
From: "Cruz, Petagay" <cruz_petagay@xxxxxxx>
Date: Wed, 13 Dec 2006 16:40:07 -0500
hi, I ran Wireshark 0.99.4 and captured 802.11 management traffic to a file.   In wireshark and can see it dissected fine.  I then used tcpreplay and replayed the pcap file on the same interface and captured that.  The new capture file shows 802.11 management messages as 'Ethernet II" or 'Ethernet Encapsulated'.  The Protocol column has various 'hex' numbers. 
 
I am using Wireshark 0.99.4,  Compiled with GTK+ 2.6.10, with GLib 2.6.6, with libpcap 0.9.4,
 
Linux RHEL4 OS, IPW2200 driver v1.1.2 Firmware version:  fw-3.0, IEEE802.11 stack version:  1.1.13
 
tcpreplay is also built with libpcap 0.9.4 and libnet 1.1.3. 
 
what am i doing wrong...
 
Maria Cruz
Associate
Booz Allen Hamilton
151 Industrial Way East
Eatontown, NJ 07724
732-935-5393