This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have created a monitor interface on an atheros card (AR922X) which is part of a separate laptop with ath9k driver. I am using wireshark to monitor the traffic in the channel through this monitor interface. I have another laptop connected to an AP in the same channel and the laptop is downloading a huge file(say a linux ISO). I get QoS data packets of size greater than 1500. Is it the actual data that is being downloaded? I tried having two devices monitor the same traffic. For a specific SN, I am getting different data on both the machines but of same length. Does this mean that this is not the downloaded data? How do i get the actual data that is part of download? To be more specific, I tried generating tcpdumps and opening them through wireshark, I am getting the same type of data as has been mentioned. Can anyone suggest what I might be missing as part of configuration? I am making sure that the flags fcsfail and control are also set. I am able to monitor LLC protocol data from other machines but this file download. It will be useful for us to know what I am missing as part of configuration.

asked 07 Mar '12, 14:01

srini_wisc's gravatar image

srini_wisc
1335
accept rate: 0%

edited 07 Mar '12, 14:17

Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×115
×86
×1

question asked: 07 Mar '12, 14:01

question was seen: 1,977 times

last updated: 07 Mar '12, 14:17

p​o​w​e​r​e​d by O​S​Q​A