Re: [tcpdump-workers] Request for DLT value

2017-04-05 Thread Guy Harris
On Apr 5, 2017, at 4:58 AM, Selvig, Bjorn wrote: > We would like to support this new header also with pcap format. Our tools > currently supports pcap format only. > > Option 1 (single DLT value) sounds a bit simpler. It allows for sniffing of > more than one protocol at a time even with pcap

Re: [tcpdump-workers] Request for DLT value

2017-04-05 Thread Guy Harris
On Apr 4, 2017, at 10:53 PM, Selvig, Bjorn wrote: > This header is for support of TI boards as sniffer adapter (LAUNCHXL boards) > for low power wireless protocols like BLE, 802.15.4 or TI proprietary > protocols. So there are two ways of handling this: 1) a single LINKTYPE_/DLT_ valu

Re: [tcpdump-workers] Request for DLT value

2017-04-04 Thread Selvig, Bjorn
, Norway. Org. NO 980499480 MVA -Original Message- From: Guy Harris [mailto:g...@alum.mit.edu] Sent: 4. april 2017 18:32 To: Selvig, Bjorn Cc: tcpdump-workers@lists.tcpdump.org Subject: Re: [tcpdump-workers] Request for DLT value On Apr 4, 2017, at 5:02 AM, Selvig, Bjorn wrote: > I am work

Re: [tcpdump-workers] Request for DLT value

2017-04-04 Thread Selvig, Bjorn
-Original Message- From: Michael Richardson [mailto:m...@sandelman.ca] Sent: 4. april 2017 15:56 To: Selvig, Bjorn Cc: tcpdump-workers@lists.tcpdump.org Subject: Re: [tcpdump-workers] Request for DLT value Selvig, Bjorn wrote: > I am working on a new header format for radio packet m

Re: [tcpdump-workers] Request for DLT value

2017-04-04 Thread Guy Harris
On Apr 4, 2017, at 5:02 AM, Selvig, Bjorn wrote: > I am working on a new header format for radio packet meta information to > display in Wireshark. For which particular link-layer protocol is this intended? ___ tcpdump-workers mailing list tcpdump-wor

Re: [tcpdump-workers] Request for DLT value for Raw LAPD

2007-10-21 Thread Guy Harris
Varuna De Silva wrote: Yes, Exactly. This is the version LAPD running between two, PABX's. OK, I've assigned the value 203 to DLT_LAPD. Note that "the packet data starts with the 2 address octets" means that the packet contains no indication of whether it's a user-to-network or network-to-u

Re: [tcpdump-workers] Request for DLT value for Raw LAPD

2007-10-20 Thread Varuna De Silva
Hello, On 10/20/07, Guy Harris <[EMAIL PROTECTED]> wrote: > > > On Oct 18, 2007, at 9:32 PM, Varuna De Silva wrote: > > > Hello, > > > > We are trying to decode raw LAPD messages tapped from a > > E1 line, with wireshark. > > So you're getting, for example, one of the E1's timeslots, which has > a

Re: [tcpdump-workers] Request for DLT value for Raw LAPD

2007-10-19 Thread Guy Harris
On Oct 18, 2007, at 9:32 PM, Varuna De Silva wrote: Hello, We are trying to decode raw LAPD messages tapped from a E1 line, with wireshark. So you're getting, for example, one of the E1's timeslots, which has an ISDN D channel on it? And the packet data starts with the 2 address octets,