Wireshark-users: Re: [Wireshark-users] Sniffing LACP traffic with wireshark
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Fri, 30 May 2014 16:01:23 -0700
On May 30, 2014, at 3:12 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:

> "-d" doesn't do filtering, it does "Decode As...".  You don't need "Decode As..." or "-d" to get Wireshark/TShark to recognize traffic with an ethertype of 0x8809 as "slow protocol" traffic or to get "slow protocol" traffic with a subtype of  0 to be recognized as LACP traffic.

Sorry, that's subtype 1, not 0, for LACP.