[Snort-users] BPF Alternative for PPPOE?

Chris Green cmg at ...1935...
Tue Jul 1 06:05:14 EDT 2003


"Richard A. Burman III" <Richard.Burman at ...9592...> writes:

> Sorry to ramble, but I wanted to be as specific as possible and hope that
> someone might have a suggestion as to what I can do.  I tried just for grins
> to see if snort treated the bpf any different than tcpdump did, but did not
> seem to have any success (with PPPOE).  In the meantime, I will read-up a
> little more on excluding hosts in the snort.conf file and welcome any
> suggestions. 

Does PPPoE create any other devices that can be used for sniffing
rather than the raw etherent device?
-- 
Chris Green <cmg at ...1935...>
You now have 14 minutes to reach minimum safe distance.




More information about the Snort-users mailing list