How to convert pcap to pcap-ng and pcap-ng to pcap?
[Linux / Wireshark Easy Explanation]
Guy Harris answered very well, but I will focus on the last question, since I believe that many (like me) are passing and going here looking for a simple explanation about converting pcapng to pcap (and vice versa). As Guy noted, not all pcap-ng files can be converted to pcap files because editcap may not work, so just do not save your packages in pcapng format, but in libcap.
pcapng β pcap
Save the captured packets in libcap format ( example - the link refers to a sample of Windows, but the same in Linux)
Open a shell on the path you are interested in and use tcpdump as follows:
tcpdump -r file_to_convert -w file_converted
(if you donβt have tcpdump, just install it using "apt-get install tcpdump" or google search if you have another Linux distribution)
pcap β pcapng
Open the pcap file with Wireshark and save it in pcapng format. You have done the conversion.
Hope this helps as it helps me.
source share