Hi,

I have this weird problem filtering out empty UDP messages on my (Linux)
firewall and in the captures I noticed something I haven't seen before.

If I capture the traffic using tcpdump and open the files using Wireshark,
I see Ethernet padding on the messages the firewall doesn't appear to
match.

Since the UDP messages are empty they are below the 64bytes minimum
Ethernet length so padding is to be expected on the wire, but I have never
before seen Ethernet padding in captures made on PC hardware running Linux.
Is this common?


-- 
Andreas Sikkema
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-requ...@wireshark.org?subject=unsubscribe

Reply via email to