Honeypots mailing list archives

Re: reassemble data from TAP


From: ADT <synfinatic () gmail com>
Date: Thu, 14 Oct 2004 12:35:08 -0700

Look at "mergecap".  It comes with Ethereal and will merge your Rx and
Tx streams into a single pcap.

-Aaron


On Thu, 14 Oct 2004 10:17:09 +0600, Vladislav V. Myasnyankin
<mvv () kazna ru> wrote:
Hello,

I want to use Snort (on Linux box)  to analyze network flow to/from
honeynet. But I have some restrictions, especially I can use only Single TAP
(http://www.securicore.ca/critical_taps/singletap/) to connect sensors. This
mean, that I need 2 NIC to receive full stream (one for Rx, one for Tx
pair). I am not sure, if Snort will work well in these conditions, because
each sensor can analyze only half of the stream.
Is there any software solution for Linux to "restore" full stream, direct it
to some pseudo-NIC, then "connect" snort to this pseudo-NIC?


-- 
http://synfin.net/


Current thread: