News: This forum is now permanently frozen.
Pages: [1]
Topic: Capture in buffer on selected interface  (Read 1122 times)
« on: May 11, 2014, 14:19:16 »
Osolemio *
Posts: 18

Would be great to have such a feature - that's very useful for troubleshooting. I'm short for it for years Smiley

- Capture all the packets BEFORE m0n0wall inspection with predefined filter (L2-L4) on selected interface (mostly physical) into a raw fixed-size file, that can be downloaded then for further  inspection in analyser. Sounds easy Cheesy

Many thanks in advance!!!!!!!!!
« Last Edit: May 11, 2014, 16:24:25 by Osolemio »
« Reply #1 on: May 11, 2014, 23:59:50 »
Lee Sharp *****
Posts: 517

The problem is where to keep the file on a system with no filespace?
« Reply #2 on: May 12, 2014, 00:20:52 »
Osolemio *
Posts: 18

and.... where uploaded firmware is kept before update? Or web GUI files?
If a PC has enough RAM - we can keep the buffer on RAM disk, for example.
« Reply #3 on: May 12, 2014, 00:24:24 »
Fred Grayson *****
Posts: 994

All of m0n0wall runs on a RAM disk as it is. The problem is that no matter how much RAM is available, the extra beyond what m0n0wall is built to use is ignored.

--
Google is your friend and Bob's your uncle.
« Reply #4 on: May 12, 2014, 00:41:27 »
Osolemio *
Posts: 18

Ok. Can we add flash card mounting with FAT32 and write onto it?
« Reply #5 on: May 12, 2014, 01:47:49 »
Osolemio *
Posts: 18

All of m0n0wall runs on a RAM disk as it is. The problem is that no matter how much RAM is available, the extra beyond what m0n0wall is built to use is ignored.


By the way, why cant you add, say 20MB empty buffer.raw file in image and rewrite it then? I cant understand then how do you change log size, settings and status, rules table that have varaiable size and so on? So there's only one way - to build it with 20MB extra space for capture buffer. It's more than enough If user sets a right filter. Even 5 MB is good Smiley But Flash Card is better of course Wink
« Last Edit: May 12, 2014, 01:57:20 by Osolemio »
« Reply #6 on: May 12, 2014, 01:56:50 »
Osolemio *
Posts: 18

to del
« Reply #7 on: May 12, 2014, 02:26:33 »
Fred Grayson *****
Posts: 994

It's open source, feel free to modify it to meet your needs and build your own images. If they are too large for others to run on their meager hardware, too bad, so sad.

--
Google is your friend and Bob's your uncle.
« Reply #8 on: May 12, 2014, 10:09:39 »
Osolemio *
Posts: 18

 Grin Of course it's open source. If you dont want to so sad...

IMHO 12MB or 17MB - it's not critical difference. It fit for any hardware.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines