tcpdump mailing list archives

Re: pcap_next_ex: Packet Data


From: Guy Harris <guy () alum mit edu>
Date: Mon, 24 Apr 2006 15:54:38 -0700


On Apr 24, 2006, at 3:23 AM, Sumit wrote:

Main difference is extra 2 bytes at the first of pcaket. Also there is not having proper destination H/W Addr; i.e. my machine's MAC, in starting bytes of packet. Do I need to set something or call some pcap routines?

One thing you need to do, if you want Ethernet headers on your packets, is capture on a device that's not the "any" device. You do *NOT* get Ethernet headers from capturing on the "any" device. You'd need to open "eth0" to capture on the eth0 adapter.

-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.


Current thread: