Hello,
My company builds hardware based network analyzers and we
are going to capture 1G/10G line rate and store in native pcap format.
If possible, it would be beneficial for us to store some
extra information in the packet headers that is unique to our ability to use
custom NIC hardware (FCS errors, collisions, etc..).
I looked at the PCAP format and am thinking there are no
spare bits / fields to accomplish this. We do plan to enable nsec timestamp
option.
Can anyone tell me if there is a way to store additional
information in the pcap file (per packet) that would not cause problems for
normal Wireshark decoding?
Thanks,
Barry
Principal Member of Technical Staff
JDSU Communication Test (formerly Acterna)
Emerging Markets and Technology
Research
One Milestone Center Court
Germantown, MD
20876
(W)
240-404-2227
(C) 240-499-4750