This is our old Q&A Site. Please post any new questions and answers at

I am doing dot1q tunnel and I use double tagging. I tag the frame with outer vlan 220, but in Wireshark, it shows vlan 1195.

Is it any conversion from 220 to 1195? or what i am seeing is not the outer vlan? Thanks!

the photo is attached:

asked 08 Nov '12, 00:22

bennettfan's gravatar image

accept rate: 0%

edited 08 Nov '12, 07:16

Jaap's gravatar image

Jaap ♦

can you please post that single packet in pcap format on

(08 Nov '12, 01:01) Kurt Knochner ♦

i don't know why i can not upload there. I just upload to google.

can you see it?

(08 Nov '12, 01:26) bennettfan

unfortunately that's not in pcap format (it's some hex dump). How did you capture the packet and how did you generate the hex dump? I need the packet in pcap format to analyze it with Wireshark.

(08 Nov '12, 01:31) Kurt Knochner ♦

how about this file? I use wireshark to print out the packet and save it.

(08 Nov '12, 01:39) bennettfan

Same format :-). Please Export the packet like this:

  • Mark the packet. Click on it then press CTRL-M
  • Wireshark 1.6: File -> Save as -> Marked Packets
  • Wireshark 1.8: File -> Export Specified Packets -> Marked Packets
(08 Nov '12, 01:56) Kurt Knochner ♦
showing 5 of 6 show 1 more comments

Wireshark only shows what is in the packet. In your first/real sample there are two 32 Bit 802.1q VLAN tag fields added:

Outer Tag: 24ac8100
Inner Tag: 20c6ffff

According to the 802.1q standard, those values contain this:

16 Bit Tag Protocol Identifier (TPID)
16 Bit Tag Control Identifier (TCI), where the last 12 Bits are the VLAN tag

Outer Tag

TPID = 0x8100 (Tagged frame)
TCI = 0x24ac. Last 12 Bits: 010010101100 == 4AC == 1196

Inner Tag

TPID = 0xffff HINT: This should be 0x800 if the remainder is an ethernet frame. 0xfff is kind of strange/wrong
TCI = 0x20c6. Last 12 Bits: 000011000110 == C6 == 198

So, as you can see Wireshark just shows what is in the packet. If that is not what you expected, there is either a problem with the part that generated that packet or the tool that captured the packet (and wrote it to a pcap file).


permanent link

answered 08 Nov '12, 19:45

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
accept rate: 15%

edited 08 Nov '12, 19:47

Noted. Thanks so much^^

(08 Nov '12, 20:36) bennettfan

If a supplied answer resolves your question can you please "accept" it by clicking the checkmark icon next to it. This highlights good answers for the benefit of subsequent users with the same or similar questions.

(09 Nov '12, 01:59) Kurt Knochner ♦

Wireshark shows a straight interpretation of the packet data it sees. Like shown on the screenshot and the packet shown through cloudshark, it is double tagged, but it seems you define the inner tag or something, not the outer.

permanent link

answered 08 Nov '12, 07:19

Jaap's gravatar image

Jaap ♦
accept rate: 14%

Below is the double tagging layer 2 frame generated by JDSU and I just post it. The outer vlan 4000 and inner vlan 50 is clearly shown.

Can anyone tell more about is it any problem with the below frame? is it the outer vlan wrong ? what is it?

(08 Nov '12, 19:27) bennettfan
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 08 Nov '12, 00:22

question was seen: 5,004 times

last updated: 09 Nov '12, 01:59

p​o​w​e​r​e​d by O​S​Q​A