Laurent Parenteau
2014-07-24 13:24:43 UTC
Hi,
I have recently used ulogd2 & netfilter to capture some traffic and
create a pcap file.
In the resulting pcap file, there is no link-layer information.
Everything else is pretty much the same as what I get from a tcpdump
capture; the only missing information is the link-layer (layer 2)
information.
In wireshark, that missing information is displayed as a "Raw packet
data" section, with the content being "No link information available".
That sits between the Frame information and the IPv4 information.
So my question is, is it possible to capture the link-layer (layer 2)
information as well using ulogd2 & netfilter, or is this a limitation
of the tools?
Thanks,
Laurent
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to ***@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
I have recently used ulogd2 & netfilter to capture some traffic and
create a pcap file.
In the resulting pcap file, there is no link-layer information.
Everything else is pretty much the same as what I get from a tcpdump
capture; the only missing information is the link-layer (layer 2)
information.
In wireshark, that missing information is displayed as a "Raw packet
data" section, with the content being "No link information available".
That sits between the Frame information and the IPv4 information.
So my question is, is it possible to capture the link-layer (layer 2)
information as well using ulogd2 & netfilter, or is this a limitation
of the tools?
Thanks,
Laurent
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to ***@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html