Hi, I have recently used ulogd2 & netfilter to capture some traffic and create a pcap file. In the resulting pcap file, there is no link-layer information. Everything else is pretty much the same as what I get from a tcpdump capture; the only missing information is the link-layer (layer 2) information. In wireshark, that missing information is displayed as a "Raw packet data" section, with the content being "No link information available". That sits between the Frame information and the IPv4 information. So my question is, is it possible to capture the link-layer (layer 2) information as well using ulogd2 & netfilter, or is this a limitation of the tools? Thanks, Laurent -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html