On 07/22/2015 01:50 AM, Todd Heberlein wrote:
If I have nprobe with PF_RING running on a box, and I want to dip in and get some raw pcap files for a short period of time, can I run tcpdump reading from the same interface? In other word, will running tcpdump interfere with nprobe?
In the past, you had a parameter called 'transparent_mode' that allowed you to configure whether captured packets would be copied to the kernel's stack (and hence, be 'visible' by libpcap) or not. Now having a look at the code it looks like it's deprecated: kernel/pf_ring.c: 391: MODULE_PARM_DESC(transparent_mode, 392: "(deprecated)"); Maybe Luca Deri can put us up to date about why it was deprecated?
Thanks, Todd
-- Regards, - AJ _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
