Re: Hiding DHCP flows
Simone Mainardi <[email protected]> Mon, 11 Nov 2019 09:57:52 +0100
| Newsgroups | gmane.linux.ntop.general |
|---|---|
| Message-ID | <[email protected]> |
--===============8483799531832375557== Content-Type: multipart/alternative; boundary="Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174" --Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii Hi, > On 9 Nov 2019, at 14:27, Michael <[email protected]> wrote: >=20 > That didn't work but I should have been more precise. This is a ZMQ = interface receiving flows from nProbe. Neither nProbe or Ntopng are = capturing. I tried running nProbe with --bpf-filter "not port bootps" = but flows between 0.0.0.0 and 255.255.255.255 still show. Is there a way = to apply this filter to Ntopng for flows received from Nprobe, or to = Nprobe for collected Netflow data? OK, in that case you have to use option --collection-filter on nProbe. = Use a /32 to exclude the single address. See: --collection-filter <filter> | Filter applied to collected = filters only (-3). Filter format: | [!]<asX | network/mask> (! means = discard flows matching filter) | Multiple filters can be defined = using multiple --collection-filter options. | Filter examples: !as12345, = 192.168.0.0/24, !10.0.0.0/8 Simone > On Thursday, November 7, 2019, 09:12:45 AM EST, Simone Mainardi = <[email protected]> wrote: >=20 >=20 > Hi, >=20 > You can use a BPF filter: >=20 > -B "not port bootps" >=20 >=20 > Simone >=20 >> On 7 Nov 2019, at 12:31, Michael <[email protected] = <mailto:[email protected]>> wrote: >>=20 >> Is there a way to hide flows for DHCP traffic? I keep seeing the = flows between 0.0.0.0 and 255.255.255.255 for clients looking for an IP = address. >> _______________________________________________ >> Ntop mailing list >> [email protected] <mailto:[email protected]> >> http://listgateway.unipi.it/mailman/listinfo/ntop >=20 > _______________________________________________ > Ntop mailing list > [email protected] <mailto:[email protected]> > http://listgateway.unipi.it/mailman/listinfo/ntop = <http://listgateway.unipi.it/mailman/listinfo/ntop>_______________________= ________________________ > Ntop mailing list > [email protected] > http://listgateway.unipi.it/mailman/listinfo/ntop --Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;" = class=3D"">Hi,<br class=3D""><div><br class=3D""><blockquote type=3D"cite"= class=3D""><div class=3D"">On 9 Nov 2019, at 14:27, Michael <<a = href=3D"mailto:[email protected]" class=3D"">[email protected]</a>> = wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div = class=3D""><div class=3D"ydp1385a98fyahoo-style-wrap" = style=3D"font-family:verdana, helvetica, = sans-serif;font-size:13px;"><div class=3D""></div> <div dir=3D"ltr" data-setdir=3D"false" class=3D"">That didn't = work but I should have been more precise. This is a ZMQ interface = receiving flows from nProbe. Neither nProbe or Ntopng are capturing. I = tried running nProbe with <b class=3D"">--bpf-filter </b><span = style=3D"font-family: Helvetica Neue, Helvetica, Arial, sans-serif;" = class=3D""><b class=3D"">"not port bootps"</b> but flows between 0.0.0.0 = a</span><span style=3D"font-family: "Helvetica Neue", = Helvetica, Arial, sans-serif;" class=3D"">nd 255.255.255.255 still show. = Is there a way to apply this filter to Ntopng for flows received from = Nprobe, or to Nprobe for collected Netflow = data?</span></div></div></div></div></blockquote><div><br = class=3D""></div><div>OK, in that case you have to use option = --collection-filter on nProbe. Use a /32 to exclude the single address. = See:</div><div><br class=3D""></div><div>--collection-filter = <filter> | Filter applied to collected = filters only (-3). Filter format:<br class=3D""> = = | [!]<asX | network/mask> (! = means discard flows matching filter)<br class=3D""> = = | Multiple filters can be defined = using multiple --collection-filter options.<br class=3D""> = = | Filter examples: !as12345, = 192.168.0.0/24, !10.0.0.0/8</div><div><br class=3D""></div><div><br = class=3D""></div><div><br class=3D""></div><div>Simone</div><br = class=3D""><blockquote type=3D"cite" class=3D""><div class=3D""><div = id=3D"yahoo_quoted_4056962075" class=3D"yahoo_quoted"> <div style=3D"font-family:'Helvetica Neue', Helvetica, = Arial, sans-serif;font-size:13px;color:#26282a;" class=3D""> =20 <div class=3D""> On Thursday, November 7, 2019, 09:12:45 AM EST, = Simone Mainardi <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>> wrote: </div> <div class=3D""><br class=3D""></div> <div class=3D""><br class=3D""></div> <div class=3D""><div id=3D"yiv3040066333" class=3D""><div = class=3D""><div class=3D"yiv3040066333">Hi,</div><div = class=3D"yiv3040066333"><br clear=3D"none" = class=3D"yiv3040066333"></div><div class=3D"yiv3040066333">You can use a = BPF filter:</div><div class=3D"yiv3040066333"><br clear=3D"none" = class=3D"yiv3040066333"></div><div class=3D"yiv3040066333">-B "not port = bootps"</div><div class=3D"yiv3040066333"><br clear=3D"none" = class=3D"yiv3040066333"></div><div class=3D"yiv3040066333"><br = clear=3D"none" class=3D"yiv3040066333"></div><div = class=3D"yiv3040066333">Simone<br clear=3D"none" = class=3D"yiv3040066333"><div class=3D""><br clear=3D"none" = class=3D"yiv3040066333"><blockquote class=3D"yiv3040066333" = type=3D"cite"><div class=3D"yiv3040066333yqt0814282840" = id=3D"yiv3040066333yqt82940"><div class=3D"yiv3040066333">On 7 Nov 2019, = at 12:31, Michael <<a rel=3D"nofollow" shape=3D"rect" = class=3D"yiv3040066333" ymailto=3D"mailto:[email protected]" = target=3D"_blank" = href=3D"mailto:[email protected]">[email protected]</a>> = wrote:</div><br clear=3D"none" = class=3D"yiv3040066333Apple-interchange-newline"><div = class=3D"yiv3040066333"><div class=3D"yiv3040066333"><div = class=3D"yiv3040066333ydpc93df093yahoo-style-wrap" = style=3D"font-family:verdana, helvetica, = sans-serif;font-size:13px;"><div class=3D"yiv3040066333" dir=3D"ltr">Is = there a way to hide flows for DHCP traffic? I keep seeing the flows = between 0.0.0.0 and 255.255.255.255 for clients looking for an IP = address.</div></div></div>_______________________________________________<= br clear=3D"none" class=3D"yiv3040066333">Ntop mailing list<br = clear=3D"none" class=3D"yiv3040066333"><a rel=3D"nofollow" shape=3D"rect" = class=3D"yiv3040066333" ymailto=3D"mailto:[email protected]" = target=3D"_blank" = href=3D"mailto:[email protected]">[email protected]</a><br= clear=3D"none" class=3D"yiv3040066333"><a = href=3D"http://listgateway.unipi.it/mailman/listinfo/ntop" = class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</a></div></di= v></blockquote></div><br clear=3D"none" = class=3D"yiv3040066333"></div></div></div><div class=3D"yqt0814282840" = id=3D"yqt94593">_______________________________________________<br = clear=3D"none" class=3D"">Ntop mailing list<br clear=3D"none" = class=3D""><a shape=3D"rect" ymailto=3D"mailto:[email protected]" = href=3D"mailto:[email protected]" = class=3D"">[email protected]</a><br clear=3D"none" class=3D""><a = shape=3D"rect" href=3D"http://listgateway.unipi.it/mailman/listinfo/ntop" = target=3D"_blank" = class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</a></div></di= v> </div> </div></div>_______________________________________________<br = class=3D"">Ntop mailing list<br class=3D""><a = href=3D"mailto:[email protected]" = class=3D"">[email protected]</a><br = class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</blockquote><= /div><br class=3D""></body></html>= --Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174-- --===============8483799531832375557== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop --===============8483799531832375557==--