https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6888
Summary: Adding support for LINKTYPE_PPP_ETHER/DLT_PPP_ETHER
Product: Wireshark
Version: 1.6.5
Platform: All
OS/Version: All
Status: NEW
Severity: Enhancement
Priority: Low
Component: Wireshark
AssignedTo: bugzilla-admin@xxxxxxxxxxxxx
ReportedBy: rspmn@xxxxxxxx
Created attachment 7926
--> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=7926
Sample DLT 51 pcap file
Build Information:
TShark 1.6.5 (SVN Rev Unknown from unknown)
Copyright 1998-2012 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (32-bit) with GLib 2.30.1, with libpcap (version unknown), with libz
1.2.5, without POSIX capabilities, without libpcre, without SMI, without
c-ares,
without ADNS, with Lua 5.1, with Python, with GnuTLS 3.0.3, with Gcrypt 1.5.0,
without Kerberos, without GeoIP.
Running on Linux 3.1.9-1.4-default, with libpcap version 1.1.1, with libz
1.2.5.
Built using gcc 4.6.2.
--
I recently noticed that Wireshark does not seem to support pcap files
with DLT 51 (LINKTYPE_PPP_ETHER/DLT_PPP_ETHER) which is used by the
in-kernel PPPoE implementation (pppoe(4)) in NetBSD and OpenBSD
$ tshark -r pppoe0-sample-2.pcap
...
tshark: The file "pppoe0-sample-2.pcap" is a capture for a network type that
TShark doesn't support.
(pcap: network type 51 unknown or unsupported)
while it is supported by tcpdump version 4.1.1/libpcap version 1.1.1
$ tcpdump -r pppoe0-sample-2.pcap
reading from file pppoe0-sample-2.pcap, link-type PPP_ETHER (PPPoE)
16:35:12.311666 PPPoE [ses 0x3b9] IP 87.151.247.51.65525 > 130.133.3.130.ftp:
Flags [S], seq 2706710675, win 32768, options [mss 1452,nop,wscale
3,sackOK,nop,nop,nop,nop,TS val 1 ecr 0], length 0
16:35:12.371770 PPPoE [ses 0x3b9] IP 130.133.3.130.ftp > 87.151.247.51.65525:
Flags [S.], seq 2929326529, ack 2706710676, win 5792, options [mss
1452,sackOK,TS val 619067066 ecr 1,nop,wscale 6], length 0
16:35:12.373509 PPPoE [ses 0x3b9] IP 87.151.247.51.65525 > 130.133.3.130.ftp:
Flags [.], ack 1, win 4174, options [nop,nop,TS val 1 ecr 619067066], length 0
...
--
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.