Wireshark-users: Re: [Wireshark-users] Question on wireless sniffing and Cisco AP modes
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Wed, 29 Apr 2009 03:07:00 -0700

On Apr 29, 2009, at 2:47 AM, Guy Harris wrote:

...that they've written a plug-in capture module
for Airopeek that opens a socket to and connects to the AP -
presumably "connecting" over UDP to port 5000, as indicated by the
dissector.

Or the AP sends packets *to* port 5000, and the capture module creates a socket and binds it to port 5000.