Hi Daniel,

I'm referring to running netsniff-ng, having it accept ERSPAN data,
and write the decapsulated data to a pcap file.

Thanks,
Doug

On Tue, Oct 22, 2013 at 4:23 AM, Daniel Borkmann <dbork...@redhat.com> wrote:
> On 10/21/2013 05:00 PM, Doug Burks wrote:
>>
>> Hello all,
>>
>> Have you considered implementing support for decoding ERSPAN?  Looks
>> like gulp and snort currently support this:
>
>
> Are you referring to the packet dissector or to store the decapsulated
> data to a pcap file?
>
>
>> http://staff.washington.edu/corey/gulp/
>> http://blog.snort.org/2013/07/snort-295-is-now-available.html
>>
>> Thanks for your consideration!
>>
>



-- 
Doug Burks
http://securityonion.blogspot.com

-- 
You received this message because you are subscribed to the Google Groups 
"netsniff-ng" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to netsniff-ng+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to