Re: PFRing filter capability

Alfredo Cardigliano <[email protected]> Mon, 30 Jul 2018 15:14:10 +0200
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
Hi
if you are using standard drivers and looking for kernel filtering, please take
a look at pfring_add_filtering_rule() in http://www.ntop.org/guides/pf_ring/api/pfring.html
you can filter based on all the fields defined in the data structure defined at
https://github.com/ntop/PF_RING/blob/dev/kernel/linux/pf_ring.h#L443

Alfredo

> On 27 Jul 2018, at 19:59, Ajit Sarnaik <[email protected]> wrote:
> 
> Hello Folks,
> 
> Has anybody used the filtering capability of PFRING please. We would like to capture DHCP request and DNS query packets and responses as well. Any pointers would be helpful.
> 
> Regards,
> 
> Ajit Sarnaik
> [email protected] <mailto:[email protected]>_______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEunYLiJIhvMrSEXzAm6qh6WCZ23EFAltfDyIACgkQm6qh6WCZ
23EINg/+PqGMiuGXRSsUdElVItFuC1WjtcirlbGffu/3IO326MpE3eDqqiFxelQp
WY6cMKOkUHnDV8VgSGoCctHa0HF3mldpo5qvInb2BCyH1Vm2QdYjQMhY7nZpMkS+
S19IPh2Sw2XUz0ZbQT+UDGfkIqc6fkRYQap9JI2+e/e9sMk0Xue7zUvkrdyUZKzE
y2Sg04onZNKGnXZ5ttU2Uy7K0rhewD3Or/14gATvTYTRzA37H+m0KhR1E7It3mgC
a9uEVBeaZdl6mbs0lp2boO9ZK+q2k92IstuqZdOmg4yi4fWvuL678bmvdYBixFVN
h1Y1dcdUmO0bEhxEKFFIYUG1UD5HcpS0Rmifa+87Onc3VZ+u38fpFuw1RHwYoBdx
CB2kiV8EJj71PjIFhukkVZzygc+fcpbtWwY5K6VAlBsa2GyjywsZ+ifMH70jmgn/
xkvdH9+DSa6yCyFLyT5Yu4AjK/Nz98lndnZgpeV+evB8EYwW/mlocrtl2pO4VVIQ
KdGWC7risx8cK1OhPhq7U33o67Q/xh6DOO9GCcMGsO0z70/prXAQk7NfA2OVSy9+
AkuO1WU9idApCO/gnGzyPephtAof3XuPNUe3nq+8IgR+14mRojJqE0oOd6/ZZTjs
8lM+BH4u2tZ0xdbS8kDGoFfsGjpQbZeppTaOA2+VJ4nnrMY0TTc=
=5o5z
-----END PGP SIGNATURE-----