Hi all, I have a problem, generating pcap files with ntop. We are using freebsd 8.2 with ntop 4.0.1 compiled from ports, I've even tried to configure the port using libpcap from ports either no: nothing change. After the generation of a pcap file if I try to read the file with tcpdump or with wireshark/tshark, cacepilot or wireshark for windows I get errors. With tcpdump the error is: tcpdump: pcap_loop: bogus savefile header With tshark the error is: tshark: The file "1.em1.pcap" appears to be damaged or corrupt. (pcap: File has 2857783296-byte packet, bigger than maximum of 65535)
I need to collect a series of pcap from ntop then put them in cacepilot for analyzing purpose. I know that this is a "well-known" problem because google returns many results about that.. but matter of fact after searching even in list I didn't find an official "solution" (if exists). I would thank you very much for your time. Maurizio _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
