[Snort-users] [!] WARNING: Not IPv4 datagram! ([ver: 0x5][len: 0xdc05])

Chris Green cmg at ...1935...
Fri Jul 19 07:18:21 EDT 2002


max valdez <max at ...6164...> writes:

> Hi Snorters
>
> I sent a message a couple of weeks ago about my snort not logging at
>all, the subject is the message i get with snort -v, is there any
>work around that might get my snort to recognize packest and actually
>log something ??

What type of traffic is on the link according to tcpdump or ethereal?

If it's an odd link encapsulation of IP, we can change the decoders
with binary packet captures.
-- 
Chris Green <cmg at ...1935...>
A watched process never cores.




More information about the Snort-users mailing list