Hi, I am copying the contents of a pcap file into another, the idea is to replace some values for another, lets say Public IP for Private IPs.
I havent changed the values yet, I am still creating a new pcap file out of the source pap file. I use the packetbuilder to build the packets with the 4 layers (ether, IP, Udp, Payload). Everything looks fine in the output file except that Wireshark shows the packets as IP packets without decoding the next layer, UDP.
I am submitting images of how it looks in both files,I will submit the code as well

Brickner wrote Feb 27, 2015 at 10:43 AM

Can you add a pcap file and the code?
It's hard to say what is the exact issue here, so it might be more fitting for a discussion rather than an issue.

