[Oisf-users] interface won't enter promiscuous mode when run suricata with --pfring

Eric Leblond eric at regit.org
Thu Aug 9 07:41:57 UTC 2012


Hello,

Le jeudi 09 août 2012 à 15:24 +0800, Delta Yeh a écrit :
> If I change the macro  in source-pfring.c
> #define LIBPFRING_REENTRANT   0
> 
> to
> 
> #define LIBPFRING_REENTRANT   1
> 
> it works.
> 
> Why I do this is because I notice that with new pfring_open, flags
>  PF_RING_REENTRANT | PF_RING_LONG_HEADER | PF_RING_PROMISC
> is set, but with old pfring_open, the   LIBPFRING_REENTRANT is 0.
> 
> 
> So my question now is why LIBPFRING_REENTRANT affect promiscuous  mode?

Something is messed up here. Suricata code looks correct for me: it
respect PF_RING API.

Are you using synchronised version of PF_RING library and driver ?

BR,

> 
> 
> 2012/8/9 Delta Yeh <delta.yeh at gmail.com>:
> > Hi,
> >     When I run suricata 1.3rc1 with --pfring, the interface won't
> > enter promiscuous mode.
> >     I have to set interface promiscuous mode manually with ifconfig to
> > make suricata works.
> >     The pfring I use  is 5.2.1 , the OS is debian 5.
> >
> >     If I start suricata with pcap , everything is OK.
> >
> >     Any suggestion?
> >
> >     Thanks  in advance.
> >
> >
> >
> >    BR
> > DeltaY
> _______________________________________________
> Oisf-users mailing list
> Oisf-users at openinfosecfoundation.org
> http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users

-- 
Eric Leblond 
Blog: http://home.regit.org/ - Portfolio: http://regit.500px.com/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20120809/915b248f/attachment.sig>


More information about the Oisf-users mailing list