tcpdump mailing list archives
Re: Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003)
From: "Gianluca Varenni" <gianluca.varenni () cacetech com>
Date: Wed, 28 Nov 2007 13:14:07 -0800
Yeah, but you cannot write a filter like "<something I don't know> tcp port 80". You need to hardcode the offsets in the packet payload.
Have a nice day GV----- Original Message ----- From: "Luis EG Ontanon" <luis.ontanon () gmail com>
To: <tcpdump-workers () lists tcpdump org> Sent: Wednesday, November 28, 2007 12:52 PMSubject: Re: [tcpdump-workers] Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003)
No, You can look at the offset at which the IP addresses of the encapsulated IP packet are in the frame and compare it to the encapsulated address as an octetsting. LuisOn Nov 28, 2007 6:38 PM, Gianluca Varenni <gianluca.varenni () cacetech com> wrote:I think the answer to this question is "no". Right? Have a nice day GV ----- Original Message ----- From: Sassone, Ed To: winpcap-users () winpcap org Sent: Tuesday, November 27, 2007 1:36 PM Subject: [Winpcap-users] Using filters with IP encapsulation (RFC 2003) Hello.Is there a way to use filters with IP encapsulation? Specifically I want to ignore the outer (encapsulation) IP header and filter on the inner IP header.Thanks http://www.ietf.org/rfc/rfc2003.txt Ed Sassone Development Director ed.sassone () autonomy com www.autonomy.comCONFIDENTIALITY NOTICE: This communication and any files or attachments transmitted with it contain information that is confidential to the sender, privileged or exempt from disclosure under applicable law. It is intended solely for the use of the individual or the entity to which it is addressed. If you are not the intended recipient(s), you are hereby notified that any use, dissemination, or copying of this communication is strictly prohibited; please do not read, copy, use or disclose the content of this communication to others. If you have received this communication in error, please forward it, in its entirety, to the network manager at administrator () etalk com and delete it. Thank you.-------------------------------------------------------------------------------- _______________________________________________ Winpcap-users mailing list Winpcap-users () winpcap org https://www.winpcap.org/mailman/listinfo/winpcap-users-- This information is top security. When you have read it, destroy yourself. -- Marshall McLuhan - This is the tcpdump-workers list.Visit https://cod.sandelman.ca/ to unsubscribe.
- This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003) Gianluca Varenni (Nov 28)
- Re: Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003) Luis EG Ontanon (Nov 28)
- Re: Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003) Gianluca Varenni (Nov 28)
- Re: Fw: [Winpcap-users] Using filters with IP encapsulation (RFC 2003) Luis EG Ontanon (Nov 28)