Hello,
        Has anyone tried changing th BPF filter code during runtime? I have
a need to modify the BPF rules without stop/starting my pcap code. Ie to change
what packets I am sent in real-time.
I am using a custom packet capture tool that uses libpcap.

I would send the tool a signal that causes it to re-read a config file with
new filter code.

I need the ability to first flush the old filter and then load a new set.
It will probably be just a simple TCP host/port combo filter.

Has anyone done this before? Any examples?

Joe.
-- 
                                          __o       _~o       __o
                                         `\<,      `\<,      `\<,
 ______________________________________(*)/_(*)__(*)/_(*)__(*)/_(*)________
 Im a 21st Century Digital Boy ... I aint got a life, but I got lotsa toys.
 *******************     Joe Elliott  [EMAIL PROTECTED]    ********************
 Phone:(650)961-6631    Cell:(650)714-3932    Inetd.Com    http://inetd.com
 --------------------------------------------------------------------------

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe

Reply via email to