As Sergio Barresi said:
>
> Well, I am hacking just now the libpcap because I have some problems with
> the token ring.
> I have a Olicom card (driver for linux 2.0.33), who support the promiscuous
> mode, but the driver use a varible RIF;
> Now I can filter using the MAC address of a host, but for every other
> filtering, the filter must calculate the RIF length for every packet. I have an
> idea how to make this, but I am a little confused (a subtle understatement :-)
> from how the parser generate the jumps.
> If someone would like to discuss this extension to the libcap can write to this
> address: sbarresi@xxxxxxxxx.
check out http://verdict.uthscsa.edu/gram/
On their I have a link to a modified tcpdump. It's a little buggy -- I left
some debug printf() statements in their. Some day I'll clean it up. But it
works. You can filter on IP address.
Once I get all the bugs out of the TR stuff, I'll have Gerald put a link on
the ethereal web page and in the documentation explaining all the steps
necessary to use an Olicom TR card for sniffing. It does work, BTW. That's
what I use here at work.
--gilbert
--
Gilbert Ramirez Voice: +1 210 358 4032
Technical Services Fax: +1 210 358 1122
University Health System San Antonio, Texas, USA