Snort mailing list archives
mpls
From: ty <tytand04 () yahoo com>
Date: Thu, 14 Jun 2007 23:08:21 -0700 (PDT)
Hello,
I need to sniff a link that uses mpls headers. Does
any one have some advice for doing this successfully?
snort can read the packets but it seems like snort
and tcpdump don't see mpls packets containiing IP/TCP
information.
Some captures are below. I updated tcpdump libpap and
snort
tcpdump version 3.9.5
libpcap version 0.9.5
snort version 2.6.1.5
These look like normal packets with 2 byte header
attached to me. Is there a way i can strip this off or
ignore it?
here's some examples of what i see
tcpdump -i eth1
21:16:06.515653 MPLS (label 7259, exp 0, [S], ttl
252), IP, length: 46
21:16:06.515656 MPLS (label 1302, exp 0, [S], ttl
253), IP, length: 46
tcpdump -x
21:16:24.308447 MPLS (label 1972, exp 0, [S], ttl
252), IP, length: 46
0x0000: 007b 41fc 4500 0028 0095 4000 7506
457d
21:16:24.308450 MPLS (label 1432, exp 0, [S], ttl
253), IP, length: 55
0x0000: 0059 81fd 4500 0033 c2c4 0000 7d11
8646
tcpdump -X
21:25:30.604609 MPLS (label 10491, exp 0, [S], ttl
253), IP, length: 46
0x0000: 028f b1fd 4500 0028 16b0 4000 7a06
cbb2 ....E..(..@.z...
21:25:30.604743 MPLS (label 100, exp 0, [S], ttl 253),
IP, length: 481
0x0000: 0006 41fd 4500 01dd 3732 0000 2411
253b ..A.E...72..$.%;
Ty
____________________________________________________________________________________
Sick sense of humor? Visit Yahoo! TV's
Comedy with an Edge to see what's on, when.
http://tv.yahoo.com/collections/222
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Sensor overload - Too much traffic for Snort box?, (continued)
- Sensor overload - Too much traffic for Snort box? Ray H. (Jun 08)
- Re: Sensor overload - Too much traffic for Snort box? Benjamin Small (Jun 08)
- Re: Sensor overload - Too much traffic for Snort box? Fábio a.k.a Fósforo (Jun 08)
- Re: Sensor overload - Too much traffic for Snort box? Ray H. (Jun 08)
- Re: Sensor overload - Too much traffic for Snort box? Matthew Watchinski (Jun 09)
- Re: Sensor overload - Too much traffic for Snort box? Ray H. (Jun 11)
- Re: Sensor overload - Too much traffic for Snort box? Matthew Watchinski (Jun 11)
- Re: Sensor overload - Too much traffic for Snort box? Ray H. (Jun 13)
- Re: Sensor overload - Too much traffic for Snort box? Nigel Houghton (Jun 14)
- Re: Sensor overload - Too much traffic for Snort box? Matthew Watchinski (Jun 14)
- mpls ty (Jun 14)
- Re: mpls Paul Melson (Jun 15)
- Re: mpls Martin Roesch (Jun 15)
- Re: mpls Matthew Watchinski (Jun 15)
- Sensor overload - Too much traffic for Snort box? Ray H. (Jun 08)
- Re: Snort memory swap usage Marc Norton (Jun 13)
