On 11/11/06, Myron Cheung <[EMAIL PROTECTED]> wrote:
(...)
But when I test libnids-1.21 with PF_RING libpcap-0.9.4, things begin to
break. First of all, there are a lot of syslog messages complaining about
"invalid tcp headers"; and secondly, no TCP traffic data has been captured.
(...)
It may sound obvious but have you configured PF_RING to capture whole
packets? libnids _must_ receive complete packets in order to be able
to do TCP reassambly and PF_RING does _not_ capture full packets by
default. Setting bucket_len to 1600 bytes show do the trick...
[]s
Tiago Alves Macambira
_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc