Common link-layer header type values used in the pcap global header.
The pcap network field stores a numeric identifier describing the link-layer
protocol of the captured packets. The full registry is maintained by tcpdump;
this map only includes the most commonly encountered values to avoid bloating
the package. The field itself remains a raw u32 — these constants are
provided purely as a convenience for callers.
NULL: number
No link-layer header (BSD loopback).
ETHERNET: number
IEEE 802.3 Ethernet.
AX25: number
AX.25 packet, with no link-layer pseudo-header.
IEEE802_5: number
IEEE 802.5 Token Ring.
ARCNET_BSD: number
ARCNET, with BSD-style header.
SLIP: number
SLIP, with no direction indication.
PPP: number
PPP, as per RFC 1661 and RFC 1662.
FDDI: number
FDDI.
RAW: number
Raw IP packet (IPv4 or IPv6) with no link layer.
IEEE802_11: number
IEEE 802.11 wireless LAN.
LINUX_SLL: number
Linux "cooked" capture encapsulation (SLL).
PPP_HDLC: number
Apple PPP-over-HDLC.
IEEE802_11_RADIOTAP: number
IEEE 802.11 plus radiotap radio header.
USB_LINUX: number
USB packets, beginning with a Linux USB header.
BLUETOOTH_HCI_H4: number
Bluetooth HCI UART transport layer.
LINUX_SLL2: number
Linux "cooked" capture encapsulation v2.