rkers@lists.tcpdump.org
Subject: Re: [tcpdump-workers] Pcap filter for local host!
On Mar 8, 2005, at 3:37 PM, erik corell wrote:
> Thank you Guy and Alex very much for your replies! A lot of good
> stuff in them. However, I need my program to be portable.
Umm, what about
> Well, one ge
chael Richardson
Subject: Re: [tcpdump-workers] Pcap filter for local host!
Erik Corell wrote:
> I am using a pcap filter to catch 90 bytes long packets on port 123 (NTP
> packets). I am only interested in the packets to and from the computer I am
> running pcap on. It is usually not a p
from the local host? (tcpdump "port 123 and host localhost" doesnt work)
*Does anyone know what I should add to the filter below in order to make it do
what I want?
Regards,
Erik Corell
/* bpf filter code for 'port 123' with a snap size of 90 bytes */
differences between different OS (BSD and Linux). Can I use sigfigs
for this? How do I access sigfigs from what I get from pcap_next?
*Is there any way of knowing what tsc was when the software clock
timestamp was made?
Regards,
Erik Corell
-
This is the tcpdump-workers list.
Visit https