[netflow-tools] "Unsupported datalink type 113"

Damien Miller djm at mindrot.org
Thu Nov 17 15:33:54 EST 2005


On Thu, 17 Nov 2005, Tony and Robyn Lewis wrote:

> Have hacked a bit and got it "working"
>
> Added the following to the lt[] table:
>        { DLT_LINUX_SLL,16, 14,  2,  1, 0xffffffff,  0x0800,   0x86dd },
>
> This, after a comparative dump of what comes in.
>
> However, it's a messy hack, and i get the feel that cooked sockets are
> gonna be very variable in these parameters.
>
> What's an elegant solution?  Speculations:
> * have a "is a PPPoE" flag which then uses this definition
> * have a "--skiplen 16 --ft_off 14 --ft_len 2 (etc etc)" set of flags,
> or a "--flags=16,14,2,(etc etc)" flags
> * autodetect? maybe this is how tcpdump knows what to do

I think a combination of the second and the third would be the most 
useful for the general case. tcpdump probably has code we can steal...

-d




More information about the netflow-tools mailing list