[Snort-users] mpls

ty tytand04 at ...131...
Fri Jun 15 02:08:21 EDT 2007


Hello, 

I need to sniff a link that uses mpls headers. Does
any one have some advice for doing this successfully? 
 snort can read the packets but it seems like snort
and tcpdump don't see mpls packets containiing IP/TCP
information. 

Some captures are below. I updated tcpdump libpap and
snort
tcpdump version 3.9.5
libpcap version 0.9.5
snort version 2.6.1.5

These look like normal packets with 2 byte header
attached to me. Is there a way i can strip this off or
ignore it? 

here's some examples of what i see

tcpdump -i eth1

21:16:06.515653 MPLS (label 7259, exp 0, [S], ttl
252), IP, length: 46
21:16:06.515656 MPLS (label 1302, exp 0, [S], ttl
253), IP, length: 46

 tcpdump -x

21:16:24.308447 MPLS (label 1972, exp 0, [S], ttl
252), IP, length: 46
        0x0000:  007b 41fc 4500 0028 0095 4000 7506
457d
21:16:24.308450 MPLS (label 1432, exp 0, [S], ttl
253), IP, length: 55
        0x0000:  0059 81fd 4500 0033 c2c4 0000 7d11
8646
        

tcpdump -X

21:25:30.604609 MPLS (label 10491, exp 0, [S], ttl
253), IP, length: 46
        0x0000:  028f b1fd 4500 0028 16b0 4000 7a06
cbb2  ....E..(.. at ...14150...
21:25:30.604743 MPLS (label 100, exp 0, [S], ttl 253),
IP, length: 481
        0x0000:  0006 41fd 4500 01dd 3732 0000 2411
253b ..A.E...72..$.%;


Ty





       
____________________________________________________________________________________
Sick sense of humor? Visit Yahoo! TV's 
Comedy with an Edge to see what's on, when. 
http://tv.yahoo.com/collections/222




More information about the Snort-users mailing list