Linux Netfilter discussions
 help / color / mirror / Atom feed
* raw packet capture based on offset
@ 2005-09-22  3:29 colorchip
  2005-09-22 19:25 ` Alexey Toptygin
  0 siblings, 1 reply; 4+ messages in thread
From: colorchip @ 2005-09-22  3:29 UTC (permalink / raw)
  To: netfilter

Hi,

I want to capture raw packets based on the ethernet source (mac) and a 16 bit identifier following the ethtype. I am unable to find a generic filter which gives me a freedom to filter the packet based on any bit length and offset from the beginning of the packet. Can anyone help?

-nks

^ permalink raw reply	[flat|nested] 4+ messages in thread
* RE: raw packet capture based on offset
@ 2005-09-22 15:56 Harrison, Bruce (CXO)
  0 siblings, 0 replies; 4+ messages in thread
From: Harrison, Bruce (CXO) @ 2005-09-22 15:56 UTC (permalink / raw)
  To: colorchip, netfilter


Do you want to do packet capture or packet filtering?  For packet
capture, have a look at tcpdump.  I know it can capture based on source
and/or destination Ethernet address.  Not sure if it can capture on the
other field that you are looking for.

Take care,

Bruce...

-----Original Message-----
From: netfilter-bounces@lists.netfilter.org
[mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of
colorchip@sify.com
Sent: Wednesday, September 21, 2005 9:29 PM
To: netfilter@lists.netfilter.org
Subject: raw packet capture based on offset

Hi,

I want to capture raw packets based on the ethernet source (mac) and a
16 bit identifier following the ethtype. I am unable to find a generic
filter which gives me a freedom to filter the packet based on any bit
length and offset from the beginning of the packet. Can anyone help?

-nks


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2005-09-23  1:57 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-09-22  3:29 raw packet capture based on offset colorchip
2005-09-22 19:25 ` Alexey Toptygin
2005-09-23  1:57   ` PPTP/IPSec multiple clients behind iptables NAT Salim
  -- strict thread matches above, loose matches on Subject: below --
2005-09-22 15:56 raw packet capture based on offset Harrison, Bruce (CXO)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox