http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2254
Guy Harris <guy@xxxxxxxxxxxx> changed:
           What    |Removed                     |Added
----------------------------------------------------------------------------
         OS/Version|Windows XP                  |All
           Platform|PC                          |All
--- Comment #1 from Guy Harris <guy@xxxxxxxxxxxx>  2008-02-11 09:56:25 GMT ---
Type: IP (0x0800)       <-------  /* The Ethernet Type field follows directly
after the VLAN TAG(s). */
as a top-level item, i.e. neither under the
Ethernet II, Src: XXX (XX:XX:XX:XX:XX:XX), Dst: YYY (YY:YY:YY:YY:YY:YY)
nor under a VLAN header, would *not* be correct; it should appear under some
top-level header, not as a top-level header itself.
Something such as
Frame 7 (1518 bytes on wire, 1518 bytes captured)
    ...
    ...
Ethernet II, Src: 3com_9f:b1:f3 (00:60:08:9f:b1:f3), Dst: AniCommu_40:ef:24
(00:40:05:40:ef:24)
    Destination: AniCommu_40:ef:24 (00:40:05:40:ef:24)
        Address: AniCommu_40:ef:24 (00:40:05:40:ef:24)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
        .... ..0. .... .... .... .... = LG bit: Globally unique address
(factory default)
    Source: 3com_9f:b1:f3 (00:60:08:9f:b1:f3)
        Address: 3com_9f:b1:f3 (00:60:08:9f:b1:f3)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
        .... ..0. .... .... .... .... = LG bit: Globally unique address
(factory default)
    Type: 802.1Q Virtual LAN (0x8100)   <------- /* VLAN TAG Protocol
Identifier, 2 Bytes. */
    000. .... .... .... = Priority: 0
    ...0 .... .... .... = CFI: 0
    .... 0000 0010 0000 = ID: 32
    Type: IP (0x0800)       <-------  /* The Ethernet Type field follows
directly
after the VLAN TAG(s). */
Internet Protocol, Src: 131.151.32.21 (131.151.32.21), Dst: 131.151.32.129
(131.151.32.129)
    Version: 4
    Header length: 20 bytes
    ...
    ...
with all the 802.1Q information under the "Ethernet II" top-level item, rather
than under a separate "802.1Q" protocol, would be a correct way of showing
that.
-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.