Greetings: I'm having trouble decoding an LWAPP encapsulated packet. Attached is a capture file with two packets. It was taken on the *wired* side of the access point, not the RF side.
The two packets are an ICMP echo request and reply. Wireshark (Version 0.99.4 (SVN Rev 19757)) is calling the packet malformed and decoding the ICMP payload (ACBDEFG....) has 802.11 Wireless LAN Management Frame Reserved Tags. The 'Frame' Section of the decode indicates that the protocols in the frame are eth:ip:udp:lwapp:wlan, but given that it is ICMP encapsulated in LWAPP, should the list be eth:ip:udp:lwapp:icmp? I tried forcing the decode as LWAPP-L3 which did not help. This is a Circo Airespace 4.0.x setup. Can Wireshark decode these types of LWAPP frames? Thank you.
lwapp-icmp.pcap
Description: Binary data
_______________________________________________ Wireshark-users mailing list [email protected] http://www.wireshark.org/mailman/listinfo/wireshark-users
