Don’t use the @/etc/ntop.conf. Whatever args you have in that file add them to the command. For example:
Ntop –i eth1 If you don’t use root - and you really shouldn’t – make sure the user (typically ntop) has all necessary file/directory permissions. G ________________________________ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Yu Wan Sent: Thursday, July 10, 2008 11:03 AM To: [email protected] Subject: Re: [Ntop] **ERROR** pcap_open_live(): 'bind: Network is down' I try with ntop @/etc/ntop.conf -i eth1, the same error 2008/7/10 Gary Gatten <[EMAIL PROTECTED]>: Specify the args you want (interface, user, etc.) on the command line. ________________________________ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Yu Wan Sent: Thursday, July 10, 2008 10:54 AM To: [email protected]; [EMAIL PROTECTED] Subject: Re: [Ntop] **ERROR** pcap_open_live(): 'bind: Network is down' Hi Yuri, Thanks for your reply. I running ntop without using the config file (issue ntop on console) without any error, but it only capture eth0, that's not my wanted. in my ocnfig file, I used --user=root, but from the running result, it show runing by user "ntop", do you think is that problem? 2008/7/10 Yuri Francalacci <[EMAIL PROTECTED]>: do you have the same error even running ntop without using the config file? Try to run ntop on interface eth0 just to check that package is working as expected. Yuri Yu Wan wrote, On 09/07/2008 17.00: > Dear ALL, > I have problem on ntop v.3.3.6 (Dag Apt RPM Repository) on CentOS 5.0 > > I have one PC with 256M memory and 2 NIC, eth0 used for management, and > eth1 was spaned from switch for my internet router. > When I run with "ntop @/etc/ntop.conf", the system complain "**ERROR** > pcap_open_live(): 'bind: Network is down'" > Please check the error message: > [EMAIL PROTECTED] ~]# ntop @/etc/ntop.conf > Processing file /etc/ntop.conf for parameters... > Thu Jul 10 06:48:44 2008 NOTE: Interface merge enabled by default > Thu Jul 10 06:48:44 2008 Initializing gdbm databases > Thu Jul 10 06:48:44 2008 ntop v.3.3.6 (Dag Apt RPM Repository) > Thu Jul 10 06:48:44 2008 Configured on Jun 12 2008 11:27:52, built on > Jun 12 2008 11:30:05. > Thu Jul 10 06:48:44 2008 Copyright 1998-2007 by Luca Deri > <[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>> > Thu Jul 10 06:48:44 2008 Get the freshest ntop from http://www.ntop.org/ > Thu Jul 10 06:48:44 2008 NOTE: ntop is running from 'ntop' > Thu Jul 10 06:48:44 2008 NOTE: (but see warning on man page for the > --instance parameter) > Thu Jul 10 06:48:44 2008 NOTE: ntop libraries are in '/usr/lib' > Thu Jul 10 06:48:44 2008 Initializing ntop > Thu Jul 10 06:48:44 2008 No patterns to load: protocol guessing disabled. > Thu Jul 10 06:48:45 2008 **ERROR** pcap_open_live(): 'bind: Network is > down' > Thu Jul 10 06:48:45 2008 Please correct the problem or select a > different interface using the -i flag > Thu Jul 10 06:48:45 2008 **FATAL_ERROR** Not root, ntop shutting down... > Thu Jul 10 06:48:45 2008 CLEANUP[t3086829248]: ntop caught signal 2 > [state=2] > Thu Jul 10 06:48:45 2008 ntop is now quitting... > > > But I was very sure the link with eth1 was up.Does anyboy who can help > me to check it? > Many thanks! > > Please check OS information: > [EMAIL PROTECTED] ~]# uname -a > Linux localhost.localdomain 2.6.18-8.el5 #1 SMP Thu Mar 15 19:57:35 EDT > 2007 i686 i686 i386 GNU/Linux > > And the way I installed the ntop > rpm -Uhv > http://apt.sw.be/redhat/el5/en/i386/rpmforge/RPMS/rpmforge-release-0.3.6-1.el5.rf.i386.rpm > yum install ntop > > The configuration of ntop: > --user root > > ### Sets the directory that ntop runs from. > --db-file-path /var/ntop > > ### Interface(s) that ntop will capture on (default: eth0) > --interface eth1 > > ### Configures ntop not to trust MAC addrs. This is used when port > mirroring or SPAN > --no-mac > > ### Logging messages to syslog (instead of the console): > ### NOTE: To log to a specific facility, use --use-syslog=local3 > ### NOTE: The = is REQUIRED and no spaces are permitted. > #--use-syslog > > ### Tells ntop to track only local hosts as specified by the > --local-subnets option > #--track-local-hosts > > ### Sets the port that the HTTP webserver listens on > ### NOTE: --http-server 3000 is the default > #--http-server 3000 > > ### Sets the port that the optional HTTPS webserver listens on > #--https-server 3001 > > ### Sets the networks that ntop should consider as local. > ### NOTE: Uses dotted decimal and CIDR notation. Example: > 192.168.0.0/24 <http://192.168.0.0/24> > ### The addresses of the interfaces are always local and don't > need to be specified. > #--local-subnets xx.xx.xx.xx/yy > ### Sets program to run as a daemon > ### NOTE: For more than casual use, you probably want this. > > > > ------------------------------------------------------------------------ > > _______________________________________________ > Ntop mailing list > [email protected] > http://listgateway.unipi.it/mailman/listinfo/ntop -- ############################################################ Yuri Francalacci E-Mail: [EMAIL PROTECTED] Internet: http://www.ntop.org/ *** Esse Quam Videri -- To Be, Rather Than To Seem *** ############################################################ _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop <font size="1"> <div style='border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 1.0pt 0in'> </div> "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." </font>
_______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
