Dear Alfredo,
                   We are using h->extended_hdr.parsed_pkt.l3_proto to
capture protocol number in this case of ARP what protocol number should be
on the look? If we parse the payload as we capture will it have effect on
the overall capture process?

Regards,
Frwa.

On Tue, Mar 19, 2013 at 4:43 PM, Alfredo Cardigliano
<[email protected]>wrote:

> Hi Frwa
> as you probably saw pfcount already detects ARP packets, if you are
> interested in the payload you have to parse it.
>
> Best Regards
> Alfredo
>
> On Mar 19, 2013, at 6:10 AM, frwa onto <[email protected]> wrote:
>
> > Dear All,
> >             What is the best mechanism to capture ARP based protocols
> via PF_RING? Do we need to decipher the payloads? For e.g. if we are using
> the sample codes from pfcount and process the payload will it have impact
> on packet capture or start to cause packet loss? Thank you.
> > _______________________________________________
> > Ntop-misc mailing list
> > [email protected]
> > http://listgateway.unipi.it/mailman/listinfo/ntop-misc
>
> _______________________________________________
> Ntop-misc mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc
>
_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc

Reply via email to