It's a long story, but we use the following BPF with ntop at one site.

--filter-expression=²not \( dst net 172.16.1.0/24 and src net 10.0.0.0/8 or
192.168.0.0/16 or  172.16.0.0/12\) or not \( src net 172.16.1.0/24 and dst
net 10.0.0.0/8 or 192.168.0.0/16 or 172.16.0.0/12\)²



Frank Eargle II
Information Security Analyst
SC Computer Incident Response Team
The Division of State Information Technology (DSIT)
4430 Broad River Rd
Columbia, SC 29210
803-896-1650 SC-ISAC Response Center
803-896-0711 Direct Line
http://sc-isac.sc.gov <blocked::http://sc-isac.sc.gov> 

_______________________________________________
Ntop-dev mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-dev

Reply via email to