ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-dev: [Ethereal-dev] New capture filters

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Diwakar Shetty <diwakar@xxxxxxxxxxxxxx>
Date: Thu, 18 Oct 2001 09:45:18 +0530
Hi

I need to add new capture filters in ethereal-0.8.18 to support two
propietory protocols.

One protocol is over PPP and the other is over UDP.

Each of the propietory protocol in turn has other propietory or internet
protocols over it....just like encapsulation / tunneling.

1) How do I go about it ??
    Do I need to
    a) change the BPF filters in side the kernel
    b) or the LibPcap source code
    c) or just use the LibPcap interfaces ??

2) This is required in both Linux and Windows version of Ethereal. So
code modifications needs to be portable.

3) The capture filter needs to be stateful. Is it possible to create a
stateful capture filter?


Thanking in advance for any pointers / guidance.....

Regards

Diwakar



*********************************************************
Disclaimer

This message (including any attachments) contains 
confidential information intended for a specific 
individual and purpose, and is protected by law. 
If you are not the intended recipient, you should 
delete this message and are hereby notified that 
any disclosure, copying, or distribution of this
message, or the taking of any action based on it, 
is strictly prohibited.

*********************************************************
Visit us at http://www.mahindrabt.com