Hi, I am sniffing traffic on a specific channel in monitor mode and I am normally capturing 802.11 frames without a problem. Yet sometimes I see packets from protocols like ICMP, SSDP, ARP etc. which probably come from a open networks in that channel. What I am trying to do is display only the 802.11 part as though the data portion of all packets would be impossible to 'translate'. Note I am not trying to filter out frames based on their protocol. I am trying to stop wireshark from going into the extra job of translating the data portion of open networks. Is that possible? Thanks for the help. asked 25 Feb '14, 02:56 BadAcidTrip |