kernel: 2.6.32-431.23.3.el6.x86_64 version RC3 with your tpacketv2 updates
The packets are only malformed in the pcap files. -i eth1 -o /nsm/pcap/$TODAY/ -s --prefix snort.log. --verbose --ring-size 50MiB --interval 50MiB Thanks Mike On Sep 25, 2014, at 3:23 AM, Tobias Klauser <[email protected]> wrote: > Hi Mike > > Thanks for your report. > > On 2014-09-24 at 19:46:18 +0200, Mike Reeves <[email protected]> wrote: >> Hey all.. I am using tpcaket v2 to capture packets and all of my packets are >> malformed. I am not loading any BPFs or anything like that. I see it >> filling up the disk and by the file size looks like it is getting the whole >> packet. Is there something simple I am missing here? > > I don't see any malformed packets here when testing with tpacketv2 on > HEAD. > > Where do the packets appear malformed, does netsniff-ng say something or > are they malformed in the pcap. What command line options were you > using? Which version of netsniff-ng? Which Linux kernel version? > > Cheers > Tobias > > -- > You received this message because you are subscribed to the Google Groups > "netsniff-ng" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- You received this message because you are subscribed to the Google Groups "netsniff-ng" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
