Wireshark-users: Re: [Wireshark-users] How to get rid of "Linux cooked capture" ?

From: Sake Blok <sake@xxxxxxxxxx>
Date: Wed, 7 Jul 2010 12:40:12 +0200
On 7 jul 2010, at 12:16, Jeanne Clément wrote:

> I would like a pcap capturing every packet on eth0 and lo. For this there is “any”, but this kind of capture brings a “Linux cooked capture” layer and I don’t what it at all.
> I want a true Ethernet layer and I don’t mind if the address is 00:00:00:00:00:00 for packets issued from lo.

You could create two separate tracefiles. One for eth0 and one for lo and then merge the two with mergecap.

Cheers,


Sake