Re: Hiding DHCP flows
Michael <[email protected]> Sat, 9 Nov 2019 13:27:34 +0000 (UTC)
| Newsgroups | gmane.linux.ntop.general |
|---|---|
| Message-ID | <[email protected]> |
--===============7089706364491896844== Content-Type: multipart/alternative; boundary="----=_Part_1972940_282116001.1573306054143" ------=_Part_1972940_282116001.1573306054143 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable That didn't work but I should have been more precise. This is a ZMQ interf= ace receiving flows from nProbe. Neither nProbe or Ntopng are capturing. I = tried running nProbe with=C2=A0--bpf-filter=C2=A0"not port bootps" but flow= s between 0.0.0.0 and 255.255.255.255 still show. Is there a way to apply t= his filter to Ntopng for flows received from Nprobe, or to Nprobe for colle= cted Netflow data? On Thursday, November 7, 2019, 09:12:45 AM EST, Simon= e Mainardi <[email protected]> wrote: =20 =20 Hi, You can use a BPF filter: -B "not port bootps" Simone On 7 Nov 2019, at 12:31, Michael <[email protected]> wrote: Is there a way to hide flows for DHCP traffic? I keep seeing the flows betw= een 0.0.0.0 and 255.255.255.255 for clients looking for an IP address._____= __________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop =20 ------=_Part_1972940_282116001.1573306054143 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <html><head></head><body><div class=3D"ydp1385a98fyahoo-style-wrap" style= =3D"font-family:verdana, helvetica, sans-serif;font-size:13px;"><div></div> <div dir=3D"ltr" data-setdir=3D"false">That didn't work but I shoul= d have been more precise. This is a ZMQ interface receiving flows from nPro= be. Neither nProbe or Ntopng are capturing. I tried running nProbe with&nbs= p;<b>--bpf-filter </b><span style=3D"font-family: Helvetica Neue, Helv= etica, Arial, sans-serif;"><b>"not port bootps"</b> but flows between 0.0.0= .0 and 255.255.255.255 still show. Is there a way to apply this filter to N= topng for flows received from Nprobe, or to Nprobe for collected Netflow da= ta?</span></div> =20 </div><div id=3D"yahoo_quoted_4056962075" class=3D"yahoo_quoted"> <div style=3D"font-family:'Helvetica Neue', Helvetica, Arial, s= ans-serif;font-size:13px;color:#26282a;"> =20 <div> On Thursday, November 7, 2019, 09:12:45 AM EST, Simone = Mainardi <[email protected]> wrote: </div> <div><br></div> <div><br></div> <div><div id=3D"yiv3040066333"><div><div class=3D"yiv304006= 6333">Hi,</div><div class=3D"yiv3040066333"><br clear=3D"none" class=3D"yiv= 3040066333"></div><div class=3D"yiv3040066333">You can use a BPF filter:</d= iv><div class=3D"yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333">= </div><div class=3D"yiv3040066333">-B "not port bootps"</div><div class=3D"= yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333"></div><div class= =3D"yiv3040066333"><br clear=3D"none" class=3D"yiv3040066333"></div><div cl= ass=3D"yiv3040066333">Simone<br clear=3D"none" class=3D"yiv3040066333"><div= ><br clear=3D"none" class=3D"yiv3040066333"><blockquote class=3D"yiv3040066= 333" type=3D"cite"><div class=3D"yiv3040066333yqt0814282840" id=3D"yiv30400= 66333yqt82940"><div class=3D"yiv3040066333">On 7 Nov 2019, at 12:31, Michae= l <<a rel=3D"nofollow" shape=3D"rect" class=3D"yiv3040066333" ymailto=3D= "mailto:[email protected]" target=3D"_blank" href=3D"mailto:srmycall@yahoo= .com">[email protected]</a>> wrote:</div><br clear=3D"none" class=3D"yi= v3040066333Apple-interchange-newline"><div class=3D"yiv3040066333"><div cla= ss=3D"yiv3040066333"><div class=3D"yiv3040066333ydpc93df093yahoo-style-wrap= " style=3D"font-family:verdana, helvetica, sans-serif;font-size:13px;"><div= class=3D"yiv3040066333" dir=3D"ltr">Is there a way to hide flows for DHCP = traffic? I keep seeing the flows between 0.0.0.0 and 255.255.255.255 for cl= ients looking for an IP address.</div></div></div>_________________________= ______________________<br clear=3D"none" class=3D"yiv3040066333">Ntop maili= ng list<br clear=3D"none" class=3D"yiv3040066333"><a rel=3D"nofollow" shape= =3D"rect" class=3D"yiv3040066333" ymailto=3D"mailto:[email protected].= it" target=3D"_blank" href=3D"mailto:[email protected]">Ntop@listga= teway.unipi.it</a><br clear=3D"none" class=3D"yiv3040066333">http://listgat= eway.unipi.it/mailman/listinfo/ntop</div></div></blockquote></div><br clear= =3D"none" class=3D"yiv3040066333"></div></div></div><div class=3D"yqt081428= 2840" id=3D"yqt94593">_______________________________________________<br cl= ear=3D"none">Ntop mailing list<br clear=3D"none"><a shape=3D"rect" ymailto= =3D"mailto:[email protected]" href=3D"mailto:[email protected]= .it">[email protected]</a><br clear=3D"none"><a shape=3D"rect" href= =3D"http://listgateway.unipi.it/mailman/listinfo/ntop" target=3D"_blank">ht= tp://listgateway.unipi.it/mailman/listinfo/ntop</a></div></div> </div> </div></body></html> ------=_Part_1972940_282116001.1573306054143-- --===============7089706364491896844== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop --===============7089706364491896844==--