This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

why there are 3 RSSI values in the radiotap header for a dual-antenna wireless card

0

packets are captured using tcpdump on a DLINK DIR825-B1 router, then I opened up the pcap file using Wireshark, an found that the 32bit bitmap of radiotap header is extended twice, and it contains three SSI signal fields. Wireshark's RSSI column only shows the value of the last one. For example, one captured radiotap shows that the first RSSI is -18dBm, the second is -24dBm and the third is -19dBm. I feel very confused, if for each antenna there is one RSSI value, there should be two RSSI values, why there are three RSSI values?

The driver I use is ath9k.

asked 20 Jun '14, 09:14

neodreamer's gravatar image

neodreamer
11112
accept rate: 0%

Some questions:

  • is it possible to post a sample capture file somewhere (google drive, dropbox, cloudshark.org)?

  • What is the firmware on that router (dd-wrt, openwrt, etc.)?

  • How did you capture (exact tcpdump parameters)?

(21 Jun '14, 17:09) Kurt Knochner ♦

the sample pcap file can be downloaded here: http://198.56.183.230/ar9223.pcap

(24 Jun '14, 16:39) neodreamer

firmware is openwrt

the command line to do the capture is: tcpdump -i mon0 -w ar9223.pcap

(24 Jun '14, 16:42) neodreamer

What's the kernel version for the version of OpenWRT you're using? There might be a driver bug where it's adding more antenna signal values than there are antennas.

(24 Jun '14, 18:52) Guy Harris ♦♦

can be downloaded here: http://198.56.183.230/ar9223.pcap

There is no reply from the server!

(25 Jun '14, 02:16) Kurt Knochner ♦

Kernel version is 3.10.36 I have no problem download the pcap file from http://198.56.183.230/ar9223.pcap

(26 Jun '14, 11:56) neodreamer
showing 5 of 6 show 1 more comments