Wireshark-users: [Wireshark-users] How to get rid of "Linux cooked capture" ?
From: Jeanne Clément <c.jeanne@xxxxxxxxxxxx>
Date: Wed, 7 Jul 2010 12:16:37 +0200

Hi,

 

I would like a pcap capturing every packet on eth0 and lo. For this there is “any”, but this kind of capture brings a “Linux cooked capture” layer and I don’t what it at all.

I want a true Ethernet layer and I don’t mind if the address is 00:00:00:00:00:00 for packets issued from lo.

 

How should I manage to get a good capture?

 

Regards

 

Clément JEANNE.

Stagiaire R&D.

 

Astellia

Tel.: +33 (0)2 99 04 80 60

Visit our web site: www.astellia.com

 



Astellia celebrates its 10th anniversary in 2010
10 years of innovation and client proximity


Ce message et tout document joint sont confidentiels et à l'intention exclusive des destinataires.
S'ils vous ont été adressés par erreur, merci d'en informer immédiatement l'expéditeur et de les détruire.
Toute copie, diffusion ou utilisation non autorisée est interdite. Tout message électronique est susceptible d'altération : Astellia décline toute responsabilité si le message ou les documents joints ont subi une quelconque modification.

This message and any attachment are confidential and intended solely to its addressees.
If you are not the intended recipient please cancel it and inform immediately the sender.
Any unauthorised copy or dissemination is prohibited. Electronic messages may be altered: Astellia shall not be liable for those circumstances.