In my ntop (2.2) reports I have a number of packets on the "Other" line for ethernet packets (under IP, ARP, OSPF and such). I dislike having things in "Others", I prefer knowing what it is (for better catching of abnormal traffic). With tcp/udp packets thats'not a problem, I can use the -p flag... but can I do the same thing for ethernet packets ?
I used a sniffer to catch these "other" packets. Looks like they are Logical Link Control frames of type 0x01a1 and 0x01a2... What I ned is a command line option or a file where I can say "Display these as LLC packets".
Does this exists already ?
Thank you
Lo�c
_______________________________________________ Ntop mailing list [EMAIL PROTECTED] http://listgateway.unipi.it/mailman/listinfo/ntop
