I have created a monitor interface on an atheros card (AR922X) which is part of a separate laptop with ath9k driver. I am using wireshark to monitor the traffic in the channel through this monitor interface. I have another laptop connected to an AP in the same channel and the laptop is downloading a huge file(say a linux ISO). I get QoS data packets of size greater than 1500. Is it the actual data that is being downloaded? I tried having two devices monitor the same traffic. For a specific SN, I am getting different data on both the machines but of same length. Does this mean that this is not the downloaded data? How do i get the actual data that is part of download? To be more specific, I tried generating tcpdumps and opening them through wireshark, I am getting the same type of data as has been mentioned. Can anyone suggest what I might be missing as part of configuration? I am making sure that the flags fcsfail and control are also set. I am able to monitor LLC protocol data from other machines but this file download. It will be useful for us to know what I am missing as part of configuration. asked 07 Mar '12, 14:01 srini_wisc edited 07 Mar '12, 14:17 |