Re: [tcpdump-workers] [RFC PATCH 0/2]: hw timestamp support

2010-08-22 Thread Guy Harris
On May 24, 2010, at 7:26 AM, Mcmillan, Scott A wrote: > This patch adds the capability to select the packet timestamp source. It > also adds support for the PACKET_TIMESTAMP Linux kernel setting to specify > the source of packet timestamps. The corresponding Linux kernel patch is > being sub

Re: [tcpdump-workers] BPF syntax extension for GTP-U (mobile ip packet)

2010-08-22 Thread Ambika Prasad Tripathy
As I know current BOF filter mechanism of TCPDUMP, only index based filter is possible to filter those IMSI, APN , MSISDN etc... by taking tunnel transport layer as a base e.g. I was to filter GTP-U packets for TEID = 23456345 Then the iindex based filter will work (we assume GTP-U header is of

Re: [tcpdump-workers] pcap_dispatch on linux 2.6 with libpcap 1.1.1

2010-08-22 Thread Guy Harris
On Aug 21, 2010, at 3:30 PM, Jim Lloyd wrote: > I have tested with the above logic while sniffing traffic on a GigE ethernet > NIC (eth0) and on the loopback device (lo). The test machine is an 8-core > Opteron with 32Gb of RAM running CentOS 5.5 with kernel 2.6.18. The traffic > generator progra

Re: [tcpdump-workers] pcap_dispatch on linux 2.6 with libpcap 1.1.1

2010-08-22 Thread Guy Harris
On Aug 22, 2010, at 11:44 PM, Guy Harris wrote: > On Aug 21, 2010, at 3:30 PM, Jim Lloyd wrote: > >> Does this mean the 512Mb memory buffer is huge overkill? > > For this application, it might be. Of course, we must bear in mind that the average human has one breast and one testicle.[*] :-)