Snort mailing list archives

Re: [!] WARNING: Not IPv4 datagram! ([ver: 0x5][len: 0xdc05])


From: Chris Green <cmg () sourcefire com>
Date: Fri, 19 Jul 2002 10:11:16 -0400

max valdez <max () garaged homeip net> writes:

Hi Snorters

I sent a message a couple of weeks ago about my snort not logging at
all, the subject is the message i get with snort -v, is there any
work around that might get my snort to recognize packest and actually
log something ??

What type of traffic is on the link according to tcpdump or ethereal?

If it's an odd link encapsulation of IP, we can change the decoders
with binary packet captures.
-- 
Chris Green <cmg () sourcefire com>
A watched process never cores.


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: