It's a long story, but we use the following BPF with ntop at one site.
--filter-expression=²not \( dst net 172.16.1.0/24 and src net 10.0.0.0/8 or 192.168.0.0/16 or 172.16.0.0/12\) or not \( src net 172.16.1.0/24 and dst net 10.0.0.0/8 or 192.168.0.0/16 or 172.16.0.0/12\)² Frank Eargle II Information Security Analyst SC Computer Incident Response Team The Division of State Information Technology (DSIT) 4430 Broad River Rd Columbia, SC 29210 803-896-1650 SC-ISAC Response Center 803-896-0711 Direct Line http://sc-isac.sc.gov <blocked::http://sc-isac.sc.gov>
_______________________________________________ Ntop-dev mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop-dev
