On 11/11/06, Myron Cheung <[EMAIL PROTECTED]> wrote:
(...)

But when I test libnids-1.21 with PF_RING libpcap-0.9.4, things begin to
break.  First of all, there are a lot of syslog messages complaining about
"invalid tcp headers"; and secondly, no TCP traffic data has been captured.

(...)

It may sound obvious but have you configured PF_RING to capture whole
packets? libnids _must_ receive complete packets in order to be able
to do TCP reassambly and PF_RING does _not_ capture full packets by
default. Setting bucket_len to 1600 bytes show do the trick...

[]s
Tiago Alves Macambira
_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc

Reply via email to