PCAP-LINKTYPE(7) FreeBSD Miscellaneous Information Manual PCAP-LINKTYPE(7)
NAME
pcap-linktype - link-layer header types supported by libpcap
DESCRIPTION
For a live capture or ``savefile'', libpcap supplies, as the return value
of the pcap_datalink(3) routine, a value that indicates the type of link-
layer header at the beginning of the packets it provides. This is not
necessarily the type of link-layer header that the packets being captured
have on the network from which they're being captured; for example,
packets from an IEEE 802.11 network might be provided by libpcap with
Ethernet headers that the network adapter or the network adapter driver
generates from the 802.11 headers. The names for those values begin with
DLT_, so they are sometimes called "DLT_ values".
The values stored in the link-layer header type field in the savefile
header are, in most but not all cases, the same as the values returned by
pcap_datalink(). The names for those values begin with LINKTYPE_.
The link-layer header types supported by libpcap are described at
https://www.tcpdump.org/linktypes.html .
SEE ALSO
pcap(3)
6 April 2020 PCAP-LINKTYPE(7)