Re: Errors with BPF filter and DAQ
Carlos Lopez via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Uhmm …. If I am not wrong, there is no option to pass bpf filter in command line …. Or there is no option according to Snort’s help. > On 18 Jan 2022, at 16:40, James Lay <[email protected]> wrote: > > Try to pass it command line instead. > > James > > On 2022-01-18 08:27, Carlos Lopez wrote: >> No … According to another user in this mailing list, BPF filters are >> not supported by daq when netmap is used on nics .. >>> On 17 Jan 2022, at 17:29, James Lay <[email protected]> >>> wrote: >>> Did you get this resolved? >>> On Thu, 2021-12-30 at 11:17 +0000, Carlos Lopez via Snort-users >>> wrote: >>> Please, any idea or help? >>> On 28 Dec 2021, at 10:29, Carlos Lopez < >>> [email protected] >>>> wrote: >>> Hi all, >>> I am trying to filter some type of traffic using BPF under Snort >>> 3.1.19.0. I have configured the following options in snort.lua: >>> packets = >>> { >>> bpf_file = '/usr/local/etc/snort/bpf.conf', >>> } >>> And my bpf file is pretty simple: >>> (ip and not proto 112) >>> … but when Snort starts returns the following error: >>> netmap DAQ configured to passive. >>> initializing daemon mode >>> child process is 70564 >>> Commencing packet processing >>> FATAL: Couldn't set DAQ instance BPF filter to '(ip and not proto >>> 112) >>> ': (-4) >>> Fatal Error, Quitting.. >>> Maybe do I need to pass this filter as a DAQ var? >>> _______________________________________________ >>> Snort-users mailing list >>> [email protected] >>> Go to this URL to change user options or unsubscribe: >>> https://lists.snort.org/mailman/listinfo/snort-users >>> To unsubscribe, send an email to: >>> [email protected] >>> Please visit >>> http://blog.snort.org >>> to stay current on all the latest Snort news! >>> Please follow these rules: >>> https://snort.org/faq/what-is-the-mailing-list-etiquette >> _______________________________________________ >> Snort-users mailing list >> [email protected] >> Go to this URL to change user options or unsubscribe: >> https://lists.snort.org/mailman/listinfo/snort-users >> To unsubscribe, send an email to: >> [email protected] >> Please visit http://blog.snort.org to stay current on all the latest >> Snort news! >> Please follow these rules: >> https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette