Interpreting Frame Control bytes in 802.11 Wireshark trace
问题 I have a Wi-Fi capture ( .pcap ) that I'm analysing and have run across what appear to me to be inconsistencies between the 802.11 spec and Wireshark's interpretation of the data. Specifically what I'm trying to pull apart is the 2-byte 802.11 Frame Control field. Taken from http://www4.ncsu.edu/~aliu3/802.bmp, the format of the Frame Control field's subfields are as follows: And below is a Wireshark screen cap of the packet that has me confused: So as per the Wireshark screenshot, the flags