On 07/10/2014 13:29, Giles Coochey wrote:
On 07/10/2014 13:14, Oliver Lagni wrote:

On my firewall I set DSCP to 101110 for real-time traffic and I clearly see it on Nprobe server on both segments, as soon as I filter with TCPDump:


I am not sure, but I think the tos value you filter with is the 3 most significant bits, so a value between 0-7

0 = 000xxxxxx
1 = 001xxxxxx
2 = 010xxxxxx
3 = 011xxxxxx
4 = 100xxxxxx
5 = 101xxxxxx
6 = 110xxxxxx
7 = 111xxxxxx

So "tos 1" filter matches your priority packets?

Argh... binary, 0xb8 should be "tos 5"

--
Regards,

Giles Coochey, CCNP, CCNA, CCNAS
NetSecSpec Ltd
+44 (0) 8444 780677
+44 (0) 7584 634135
http://www.coochey.net
http://www.netsecspec.co.uk
gi...@coochey.net


--
Regards,

Giles Coochey, CCNP, CCNA, CCNAS
NetSecSpec Ltd
+44 (0) 8444 780677
+44 (0) 7584 634135
http://www.coochey.net
http://www.netsecspec.co.uk
gi...@coochey.net

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

------------------------------------------------------------------------------
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk
_______________________________________________
Nfsen-discuss mailing list
Nfsen-discuss@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss

Reply via email to