tcpdump mailing list archives
question regarding bpf_program
From: "Prashant Batra (prbatra)" <prbatra () cisco com>
Date: Sun, 5 Feb 2012 01:32:56 +0530
Hi All, I want to use "pcap_compile" to get a bpf filter from a string. And then I want to use the filter in the form of sock_filter to set as a socket option to capture the packets specified by the filter. I want to receive the filtered packets using PF_PACKET family socket. But what I have observed is that the filter obtained using pcap_compile (printed using bpf_dump) does not match the one using tcpdump -d option. Can someone help? Or, what should be the best way to achieve this? Regards, Prashant - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- question regarding bpf_program Prashant Batra (prbatra) (Feb 04)
- Re: question regarding bpf_program Guy Harris (Feb 04)
- Re: question regarding bpf_program Prashant Batra (prbatra) (Feb 04)
- Re: question regarding bpf_program Guy Harris (Feb 04)
- Re: question regarding bpf_program Prashant Batra (prbatra) (Feb 05)
- Re: question regarding bpf_program Prashant Batra (prbatra) (Feb 04)
- Re: question regarding bpf_program Guy Harris (Feb 04)