On 12/1/06, Kevin D. Clark <kclark at elbrysnetworks.com> wrote: > Some pcap libraries encapsulate LCP and other link layer protocols > inside pseudo-ethernet frames and can pass them right up to things > like Wireshark. I've even heard of people doing this on Windows. Ah. I didn't know that. Neat. -- Ben