7. pcapngの現状
ツールの対応状況が追いついていない
Wiresharkの現状
https://wiki.wireshark.org/Development/PcapNg
The current limitations for pcapng format are:
Only a single section
Only blocks SHB, IDB, PB, EPB, SPB (others will be ignored)
Lots of Options not implemented
Writing files is mostly untested
When merging files, mergecap doesn't retain each IDB's snaplen
mergecap won't merge pcapng files with different encapsulations and
intermixed timestamps
というか放置状態・・・?
defaultになったのは2012年
あまりアップデートはない