This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

need info on Wireshark data

0

I have created a monitor interface on an atheros card (AR922X) which is part of a separate laptop with ath9k driver. I am using wireshark to monitor the traffic in the channel through this monitor interface. I have another laptop connected to an AP in the same channel and the laptop is downloading a huge file(say a linux ISO). I get QoS data packets of size greater than 1500. Is it the actual data that is being downloaded? I tried having two devices monitor the same traffic. For a specific SN, I am getting different data on both the machines but of same length. Does this mean that this is not the downloaded data? How do i get the actual data that is part of download? To be more specific, I tried generating tcpdumps and opening them through wireshark, I am getting the same type of data as has been mentioned. Can anyone suggest what I might be missing as part of configuration? I am making sure that the flags fcsfail and control are also set. I am able to monitor LLC protocol data from other machines but this file download. It will be useful for us to know what I am missing as part of configuration.

asked 07 Mar '12, 14:01

srini_wisc's gravatar image

srini_wisc
1335
accept rate: 0%

edited 07 Mar '12, 14:17