|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » Cannot see IPv6 output ... Snort finds packets OK ... tried this post on "Support" - no responses - trying again here ...
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Cannot see IPv6 output ... Snort finds packets OK ... tried this post on "Support" - no responses - trying again here ...
Posted by JohnSpence on May 19, 2005 14:46:44
I'm running Snort, trying the IPv6 functionality - just looking for the "sniffing" capability. I see there are 4 existing Snort rules for IPv6. When I run the current code (2.3.3), on a machine with IPv6 traffic, I get summary but no detail. Is the IPv6 support lacking that part?
Thanks for any insight.
------------- screen output --------
[root@lisa root]# snort -vCX -n 2 ip6
Running in packet dump mode
Initializing Network Interface eth0
--== Initializing Snort ==--
Initializing Output Plugins!
Decoding Ethernet on interface eth0
--== Initialization Complete ==--
,,_ -*> Snort! <*-
o" )~ Version 2.3.3 (Build 14)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/team.html
(C) Copyright 1998-2004 Sourcefire Inc., et al.
Run time for packet processing was 5.196243 seconds
===============================================================================
Snort received 2 packets
Analyzed: 2(100.000%)
Dropped: 0(0.000%)
===============================================================================
Breakdown by protocol:
TCP: 0 (0.000%)
UDP: 0 (0.000%)
ICMP: 0 (0.000%)
ARP: 0 (0.000%)
EAPOL: 0 (0.000%)
IPv6: 2 (100.000%)
IPX: 0 (0.000%)
OTHER: 0 (0.000%)
DISCARD: 0 (0.000%)
===============================================================================
Action Stats:
ALERTS: 0
LOGGED: 0
PASSED: 0
===============================================================================
Snort exiting
|
|
Posted by chris on May 20, 2005 05:21:46
HI John, I'm not certain on this, but there are some posts on the net suggesting that the IPv6 traffic is only counted but not analysed, check here -
http://archives.neohapsis.com/archives/snort/2004-05/0246.html
I've also found a message from marty, regarding an experimental IPv6 decoder here
http://www.sikurezza.org/ml/12_02/msg00178.html
however the link to the decoder on the page doesn't work,
I hope this helps,
Cheers
Chris
|
|
|
|
|
|