This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,

I am sniffing traffic on a specific channel in monitor mode and I am normally capturing 802.11 frames without a problem. Yet sometimes I see packets from protocols like ICMP, SSDP, ARP etc. which probably come from a open networks in that channel.

What I am trying to do is display only the 802.11 part as though the data portion of all packets would be impossible to 'translate'. Note I am not trying to filter out frames based on their protocol. I am trying to stop wireshark from going into the extra job of translating the data portion of open networks.

Is that possible? Thanks for the help.

asked 25 Feb '14, 02:56

BadAcidTrip's gravatar image

BadAcidTrip
16334
accept rate: 0%

Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×114
×20

question asked: 25 Feb '14, 02:56

question was seen: 883 times

last updated: 25 Feb '14, 02:56

p​o​w​e​r​e​d by O​S​Q​A