On Apr 5, 2017, at 4:58 AM, Selvig, Bjorn <b.sel...@ti.com> wrote: > We would like to support this new header also with pcap format. Our tools > currently supports pcap format only. > > Option 1 (single DLT value) sounds a bit simpler. It allows for sniffing of > more than one protocol at a time even with pcap format If I understand > correctly, for example sniffing of BLE and 802.15.4 packets simultaneously. > > As a first step, is it OK to go for a single DLT for this proposed header?
Anything's OK as long as I don't have to spend any time supporting it. If somebody else wants to handle this DLT, go ahead. I won't spend any more time on it, either here or in tcpdump or in Wireshark; life's too short to deal with these "multiple types of link layer" LINKTYPE_/DLT_ values. _______________________________________________ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers