[Snort-devel] Snort 1.8.6 and PPPoE links

C.J.O. cjo at ...37...
Mon Jun 24 08:02:00 EDT 2002

Please find attached "pppoe.cap", containing 94 packets which have been 
obtained using the tcpdump parameters as instructed below.  If this isn't 
what's required, please advise.


Christopher J. Oliver

At 10:02 AM 24/06/2002 -0400, you wrote:
>"C.J.O." <cjo at ...37...> writes:
> > I'm running snort 1.8.6 in daemon mode and logging in binary format,
> > and have been experiencing some "issues".
> >
> > This particular sensor is snorting via a NIC running stealth, which
> > has been positioned directly behind a DSL modem with PPPoE
> > connectivity.  Therefore the snort sensor is "seeing" raw PPPoE.
>For us to do new link protocol decodes, please send tcpdump formatted
>files from tcpdump -i interface -s 1514 -w pppoe.cap
-------------- next part --------------
A non-text attachment was scrubbed...
Name: pppoe.cap
Type: application/octet-stream
Size: 41876 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20020624/f6334e8e/attachment.obj>

More information about the Snort-devel mailing list