Re: Packet dumping or mirroring

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Good afternoon, Michael,

On Wed, 18 Feb 2004, William Stearns wrote:

> On Wed, 18 Feb 2004, Michael Gale wrote:
> 
> > First you create a "tmpfs" .. for example in your NTOP home directory call it
> > tmp (/home/ntop/tmp). Now make this directory a RAM drive that gets mount
> > everytime we boot up, about 50MB (maybe).
> > 
> > Now we create a module for iptables to send a copy of every packet on every
> > interface to the RAM drive or dummy device.
> > 
> > What do you think ... I do not believe there is a way to do this now :(
> 
> 	You seem to be describing ulogd:
> http://www.stearns.org/doc/iptables-ulog.current.html
> 	(with pointers to other relevant sites).  You'd instruct ulogd to 
> save its files to a ramdisk as opposed to a physical disk.

	BTW, ntop will gladly read from pcap files (the "-f" parameter;  
see http://www.stearns.org/doc/pcap-apps.html ).
	Cheers,
	- Bill

---------------------------------------------------------------------------
        Santa Clara, CA (Reuters): Sources close to the spiritual leader
of the Linux movement report that Linus Torvalds has entered his 23rd
day of fasting.  The move is apparently not for religious reasons. 
"I've spent so much time looking at vomit-producing code, that Tove
refuses to feed me any more, and gives me Karate chops whenever I even
threaten to blow chunks.  Our carpet cleaning bill exceeds our mortgage. 
Hell, the ISDN subsystem alone turned our favourite Persian rug into a
monstrosity that college students won't even pick up off the street
corner.  With Jeff Dike's memory management code coming up, I thought
I'd best be prepared."
        -- WLS
--------------------------------------------------------------------------
William Stearns (wstearns@xxxxxxxxx).  Mason, Buildkernel, freedups, p0f,
rsync-backup, ssh-keyinstall, dns-check, more at:   http://www.stearns.org
--------------------------------------------------------------------------



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux