[Oisf-users] interface won't enter promiscuous mode when run suricata with --pfring
Eric Leblond
eric at regit.org
Thu Aug 9 07:41:57 UTC 2012
Hello,
Le jeudi 09 août 2012 à 15:24 +0800, Delta Yeh a écrit :
> If I change the macro in source-pfring.c
> #define LIBPFRING_REENTRANT 0
>
> to
>
> #define LIBPFRING_REENTRANT 1
>
> it works.
>
> Why I do this is because I notice that with new pfring_open, flags
> PF_RING_REENTRANT | PF_RING_LONG_HEADER | PF_RING_PROMISC
> is set, but with old pfring_open, the LIBPFRING_REENTRANT is 0.
>
>
> So my question now is why LIBPFRING_REENTRANT affect promiscuous mode?
Something is messed up here. Suricata code looks correct for me: it
respect PF_RING API.
Are you using synchronised version of PF_RING library and driver ?
BR,
>
>
> 2012/8/9 Delta Yeh <delta.yeh at gmail.com>:
> > Hi,
> > When I run suricata 1.3rc1 with --pfring, the interface won't
> > enter promiscuous mode.
> > I have to set interface promiscuous mode manually with ifconfig to
> > make suricata works.
> > The pfring I use is 5.2.1 , the OS is debian 5.
> >
> > If I start suricata with pcap , everything is OK.
> >
> > Any suggestion?
> >
> > Thanks in advance.
> >
> >
> >
> > BR
> > DeltaY
> _______________________________________________
> Oisf-users mailing list
> Oisf-users at openinfosecfoundation.org
> http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
--
Eric Leblond
Blog: http://home.regit.org/ - Portfolio: http://regit.500px.com/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20120809/915b248f/attachment.sig>
More information about the Oisf-users
mailing list