On Sun, Dec 17, 2000 at 07:49:51PM -0500, Michael Richardson wrote:
>   The only way that I see in the current tcpdump framework would be for there
> to be another flag to indicate some additional offset before the layer 3
> stuff.

Or a flag to say "capture only PPPoE data and, for all filter
expressions above the link layer, first check that the code field of the
PPPoE header is 0, and then do the tests as if this were PPP, with the
link-layer and PPPoE headers in front of the raw PPP header".

>   Ethereal has some other mechanisms,

It has other mechanisms for doing filtering of packets you've already
captured, but it just uses libpcap filters for capture filters, so it
has the same limitations as tcpdump when capturing.
-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe

Reply via email to