Re: Hiding DHCP flows

Michael <[email protected]> Sat, 9 Nov 2019 13:27:34 +0000 (UTC)
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
--===============7089706364491896844==
Content-Type: multipart/alternative; 
	boundary="----=_Part_1972940_282116001.1573306054143"

------=_Part_1972940_282116001.1573306054143
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

 That didn't work but I should have been more precise. This is a ZMQ interf=
ace receiving flows from nProbe. Neither nProbe or Ntopng are capturing. I =
tried running nProbe with=C2=A0--bpf-filter=C2=A0"not port bootps" but flow=
s between 0.0.0.0 and 255.255.255.255 still show. Is there a way to apply t=
his filter to Ntopng for flows received from Nprobe, or to Nprobe for colle=
cted Netflow data?    On Thursday, November 7, 2019, 09:12:45 AM EST, Simon=
e Mainardi <[email protected]> wrote: =20
=20
 Hi,
You can use a BPF filter:
-B "not port bootps"

Simone


On 7 Nov 2019, at 12:31, Michael <[email protected]> wrote:
Is there a way to hide flows for DHCP traffic? I keep seeing the flows betw=
een 0.0.0.0 and 255.255.255.255 for clients looking for an IP address._____=
__________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop =20
------=_Part_1972940_282116001.1573306054143
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><div class=3D"ydp1385a98fyahoo-style-wrap" style=
=3D"font-family:verdana, helvetica, sans-serif;font-size:13px;"><div></div>
        <div dir=3D"ltr" data-setdir=3D"false">That didn't work but I shoul=
d have been more precise. This is a ZMQ interface receiving flows from nPro=
be. Neither nProbe or Ntopng are capturing. I tried running nProbe with&nbs=
p;<b>--bpf-filter&nbsp;</b><span style=3D"font-family: Helvetica Neue, Helv=
etica, Arial, sans-serif;"><b>"not port bootps"</b> but flows between 0.0.0=
.0 and 255.255.255.255 still show. Is there a way to apply this filter to N=
topng for flows received from Nprobe, or to Nprobe for collected Netflow da=
ta?</span></div>
       =20
        </div><div id=3D"yahoo_quoted_4056962075" class=3D"yahoo_quoted">
            <div style=3D"font-family:'Helvetica Neue', Helvetica, Arial, s=
ans-serif;font-size:13px;color:#26282a;">
               =20
                <div>
                    On Thursday, November 7, 2019, 09:12:45 AM EST, Simone =
Mainardi &lt;[email protected]&gt; wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div><div id=3D"yiv3040066333"><div><div class=3D"yiv304006=
6333">Hi,</div><div class=3D"yiv3040066333"><br clear=3D"none" class=3D"yiv=
3040066333"></div><div class=3D"yiv3040066333">You can use a BPF filter:</d=
iv><div class=3D"yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333">=
</div><div class=3D"yiv3040066333">-B "not port bootps"</div><div class=3D"=
yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333"></div><div class=
=3D"yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333"></div><div cl=
ass=3D"yiv3040066333">Simone<br clear=3D"none" class=3D"yiv3040066333"><div=
><br clear=3D"none" class=3D"yiv3040066333"><blockquote class=3D"yiv3040066=
333" type=3D"cite"><div class=3D"yiv3040066333yqt0814282840" id=3D"yiv30400=
66333yqt82940"><div class=3D"yiv3040066333">On 7 Nov 2019, at 12:31, Michae=
l &lt;<a rel=3D"nofollow" shape=3D"rect" class=3D"yiv3040066333" ymailto=3D=
"mailto:[email protected]" target=3D"_blank" href=3D"mailto:srmycall@yahoo=
.com">[email protected]</a>&gt; wrote:</div><br clear=3D"none" class=3D"yi=
v3040066333Apple-interchange-newline"><div class=3D"yiv3040066333"><div cla=
ss=3D"yiv3040066333"><div class=3D"yiv3040066333ydpc93df093yahoo-style-wrap=
" style=3D"font-family:verdana, helvetica, sans-serif;font-size:13px;"><div=
 class=3D"yiv3040066333" dir=3D"ltr">Is there a way to hide flows for DHCP =
traffic? I keep seeing the flows between 0.0.0.0 and 255.255.255.255 for cl=
ients looking for an IP address.</div></div></div>_________________________=
______________________<br clear=3D"none" class=3D"yiv3040066333">Ntop maili=
ng list<br clear=3D"none" class=3D"yiv3040066333"><a rel=3D"nofollow" shape=
=3D"rect" class=3D"yiv3040066333" ymailto=3D"mailto:[email protected].=
it" target=3D"_blank" href=3D"mailto:[email protected]">Ntop@listga=
teway.unipi.it</a><br clear=3D"none" class=3D"yiv3040066333">http://listgat=
eway.unipi.it/mailman/listinfo/ntop</div></div></blockquote></div><br clear=
=3D"none" class=3D"yiv3040066333"></div></div></div><div class=3D"yqt081428=
2840" id=3D"yqt94593">_______________________________________________<br cl=
ear=3D"none">Ntop mailing list<br clear=3D"none"><a shape=3D"rect" ymailto=
=3D"mailto:[email protected]" href=3D"mailto:[email protected]=
.it">[email protected]</a><br clear=3D"none"><a shape=3D"rect" href=
=3D"http://listgateway.unipi.it/mailman/listinfo/ntop" target=3D"_blank">ht=
tp://listgateway.unipi.it/mailman/listinfo/ntop</a></div></div>
            </div>
        </div></body></html>
------=_Part_1972940_282116001.1573306054143--

--===============7089706364491896844==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
--===============7089706364491896844==--