Hello folks, I was trying to capture promiscuous traffic using libpcap 0.6.2 on Linux. On my multi interface box, I have some span port traffic coming into eth0. When I captured on the eth0 interface promiscousouly, I can see the traffic coming in (which is not addressed to the eth0 address). But when I want to do the same thing on the "any" (cooked mode) interface in the hope of capturing such traffic on all interfaces, I dont see any traffic, not even the eth0 traffic.
The man page did indicate some issue with promiscuous capture on the "any" interface. I wanted to confirm this. Also, if this is a recognized issue in 0.6.2, has there been any sort of resolution in later (cvs) releases? I would appreciate any suggestions in case it needs to be patched. Thanks, Joe __________________________________________________ Do you Yahoo!? Yahoo! Mail Plus - Powerful. Affordable. Sign up now. http://mailplus.yahoo.com - This is the TCPDUMP workers list. It is archived at http://www.tcpdump.org/lists/workers/index.html To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe
