Snort mailing list archives

Re: Snort 1.8.7b6 not listen to BPF filters


From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 19 Jul 2002 11:42:11 -0700 (PDT)

On Fri, 19 Jul 2002, Michael Scheidell wrote:

I have had the same problem since 1.8.6.x
Sent in several requests for guidance, none of them have been very helpful
so far.

A couple of things here:

        1)  Update to 1.8.7 since it's been released and has many bugfixes
backported from 1.9 into it.
        2)  try it without using a "file".

                snort <options> 'not host foo'
        3)  compile with debug and set DEBUG_INIT and DEBUG_CONFIGURES, then
fire off with and without using the -F option.  See if there's anything odd
going on.

Cause the wierd part is I don't have a problem with BPF's working.  Could it
be your pcap?  I'm using the 0.7.1.tar.gz from tcpdump.org.

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: