Re: Hiding DHCP flows

Simone Mainardi <[email protected]> Mon, 11 Nov 2019 09:57:52 +0100
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
--===============8483799531832375557==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174"


--Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hi,

> On 9 Nov 2019, at 14:27, Michael <[email protected]> wrote:
>=20
> That didn't work but I should have been more precise. This is a ZMQ =
interface receiving flows from nProbe. Neither nProbe or Ntopng are =
capturing. I tried running nProbe with --bpf-filter "not port bootps" =
but flows between 0.0.0.0 and 255.255.255.255 still show. Is there a way =
to apply this filter to Ntopng for flows received from Nprobe, or to =
Nprobe for collected Netflow data?

OK, in that case you have to use option --collection-filter on nProbe. =
Use a /32 to exclude the single address. See:

--collection-filter <filter>        | Filter applied to collected =
filters only (-3). Filter format:
                                    | [!]<asX | network/mask> (! means =
discard flows matching filter)
                                    | Multiple filters can be defined =
using multiple --collection-filter options.
                                    | Filter examples: !as12345, =
192.168.0.0/24, !10.0.0.0/8



Simone

> On Thursday, November 7, 2019, 09:12:45 AM EST, Simone Mainardi =
<[email protected]> wrote:
>=20
>=20
> Hi,
>=20
> You can use a BPF filter:
>=20
> -B "not port bootps"
>=20
>=20
> Simone
>=20
>> On 7 Nov 2019, at 12:31, Michael <[email protected] =
<mailto:[email protected]>> wrote:
>>=20
>> Is there a way to hide flows for DHCP traffic? I keep seeing the =
flows between 0.0.0.0 and 255.255.255.255 for clients looking for an IP =
address.
>> _______________________________________________
>> Ntop mailing list
>> [email protected] <mailto:[email protected]>
>> http://listgateway.unipi.it/mailman/listinfo/ntop
>=20
> _______________________________________________
> Ntop mailing list
> [email protected] <mailto:[email protected]>
> http://listgateway.unipi.it/mailman/listinfo/ntop =
<http://listgateway.unipi.it/mailman/listinfo/ntop>_______________________=
________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop


--Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Hi,<br class=3D""><div><br class=3D""><blockquote type=3D"cite"=
 class=3D""><div class=3D"">On 9 Nov 2019, at 14:27, Michael &lt;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
class=3D""><div class=3D"ydp1385a98fyahoo-style-wrap" =
style=3D"font-family:verdana, helvetica, =
sans-serif;font-size:13px;"><div class=3D""></div>
        <div dir=3D"ltr" data-setdir=3D"false" class=3D"">That didn't =
work but I should have been more precise. This is a ZMQ interface =
receiving flows from nProbe. Neither nProbe or Ntopng are capturing. I =
tried running nProbe with&nbsp;<b class=3D"">--bpf-filter&nbsp;</b><span =
style=3D"font-family: Helvetica Neue, Helvetica, Arial, sans-serif;" =
class=3D""><b class=3D"">"not port bootps"</b> but flows between 0.0.0.0 =
a</span><span style=3D"font-family: &quot;Helvetica Neue&quot;, =
Helvetica, Arial, sans-serif;" class=3D"">nd 255.255.255.255 still show. =
Is there a way to apply this filter to Ntopng for flows received from =
Nprobe, or to Nprobe for collected Netflow =
data?</span></div></div></div></div></blockquote><div><br =
class=3D""></div><div>OK, in that case you have to use option =
--collection-filter on nProbe. Use a /32 to exclude the single address. =
See:</div><div><br class=3D""></div><div>--collection-filter =
&lt;filter&gt; &nbsp; &nbsp; &nbsp; &nbsp;| Filter applied to collected =
filters only (-3). Filter format:<br class=3D"">&nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | [!]&lt;asX | network/mask&gt; (! =
means discard flows matching filter)<br class=3D"">&nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | Multiple filters can be defined =
using multiple --collection-filter options.<br class=3D"">&nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | Filter examples: !as12345, =
192.168.0.0/24, !10.0.0.0/8</div><div><br class=3D""></div><div><br =
class=3D""></div><div><br class=3D""></div><div>Simone</div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D""><div =
id=3D"yahoo_quoted_4056962075" class=3D"yahoo_quoted">
            <div style=3D"font-family:'Helvetica Neue', Helvetica, =
Arial, sans-serif;font-size:13px;color:#26282a;" class=3D"">
               =20
                <div class=3D"">
                    On Thursday, November 7, 2019, 09:12:45 AM EST, =
Simone Mainardi &lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:
                </div>
                <div class=3D""><br class=3D""></div>
                <div class=3D""><br class=3D""></div>
                <div class=3D""><div id=3D"yiv3040066333" class=3D""><div =
class=3D""><div class=3D"yiv3040066333">Hi,</div><div =
class=3D"yiv3040066333"><br clear=3D"none" =
class=3D"yiv3040066333"></div><div class=3D"yiv3040066333">You can use a =
BPF filter:</div><div class=3D"yiv3040066333"><br clear=3D"none" =
class=3D"yiv3040066333"></div><div class=3D"yiv3040066333">-B "not port =
bootps"</div><div class=3D"yiv3040066333"><br clear=3D"none" =
class=3D"yiv3040066333"></div><div class=3D"yiv3040066333"><br =
clear=3D"none" class=3D"yiv3040066333"></div><div =
class=3D"yiv3040066333">Simone<br clear=3D"none" =
class=3D"yiv3040066333"><div class=3D""><br clear=3D"none" =
class=3D"yiv3040066333"><blockquote class=3D"yiv3040066333" =
type=3D"cite"><div class=3D"yiv3040066333yqt0814282840" =
id=3D"yiv3040066333yqt82940"><div class=3D"yiv3040066333">On 7 Nov 2019, =
at 12:31, Michael &lt;<a rel=3D"nofollow" shape=3D"rect" =
class=3D"yiv3040066333" ymailto=3D"mailto:[email protected]" =
target=3D"_blank" =
href=3D"mailto:[email protected]">[email protected]</a>&gt; =
wrote:</div><br clear=3D"none" =
class=3D"yiv3040066333Apple-interchange-newline"><div =
class=3D"yiv3040066333"><div class=3D"yiv3040066333"><div =
class=3D"yiv3040066333ydpc93df093yahoo-style-wrap" =
style=3D"font-family:verdana, helvetica, =
sans-serif;font-size:13px;"><div class=3D"yiv3040066333" dir=3D"ltr">Is =
there a way to hide flows for DHCP traffic? I keep seeing the flows =
between 0.0.0.0 and 255.255.255.255 for clients looking for an IP =
address.</div></div></div>_______________________________________________<=
br clear=3D"none" class=3D"yiv3040066333">Ntop mailing list<br =
clear=3D"none" class=3D"yiv3040066333"><a rel=3D"nofollow" shape=3D"rect" =
class=3D"yiv3040066333" ymailto=3D"mailto:[email protected]" =
target=3D"_blank" =
href=3D"mailto:[email protected]">[email protected]</a><br=
 clear=3D"none" class=3D"yiv3040066333"><a =
href=3D"http://listgateway.unipi.it/mailman/listinfo/ntop" =
class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</a></div></di=
v></blockquote></div><br clear=3D"none" =
class=3D"yiv3040066333"></div></div></div><div class=3D"yqt0814282840" =
id=3D"yqt94593">_______________________________________________<br =
clear=3D"none" class=3D"">Ntop mailing list<br clear=3D"none" =
class=3D""><a shape=3D"rect" ymailto=3D"mailto:[email protected]" =
href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a><br clear=3D"none" class=3D""><a =
shape=3D"rect" href=3D"http://listgateway.unipi.it/mailman/listinfo/ntop" =
target=3D"_blank" =
class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</a></div></di=
v>
            </div>
        </div></div>_______________________________________________<br =
class=3D"">Ntop mailing list<br class=3D""><a =
href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a><br =
class=3D"">http://listgateway.unipi.it/mailman/listinfo/ntop</blockquote><=
/div><br class=3D""></body></html>=

--Apple-Mail=_85960563-754F-45DC-890D-8A45ACFE1174--

--===============8483799531832375557==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
--===============8483799531832375557==--