1999-04-03 01:51:01 +00:00
|
|
|
bpft is a superset of trafshow, and extends it by adding a daemon
|
|
|
|
which collects data about network connections (src, dst, protocol
|
|
|
|
and length). The resulting data can be dumped to a file for later
|
|
|
|
processing.
|
|
|
|
|
|
|
|
Read /usr/local/share/doc/bpft/README after installation for more
|
|
|
|
information.
|
|
|
|
|
|
|
|
To use bpft, your kernel must be rebuilt with the following line
|
|
|
|
added to your kernel config file (/sys/i386/conf/<YourMachine>):
|
|
|
|
|
|
|
|
pseudo-device bpfilter 4 # Berkeley packet filter
|
|
|
|
|
|
|
|
The number after bpfilter is the number of interfaces that can be
|
|
|
|
examined simultaneously. See section 6.1 of the Handbook for details.
|
|
|
|
|
2001-01-03 19:44:28 +00:00
|
|
|
On FreeBSD 4 or later, use the following line instead:
|
1999-10-25 18:32:33 +00:00
|
|
|
|
2001-01-03 19:44:28 +00:00
|
|
|
device bpf # Berkeley packet filter
|
1999-10-25 18:32:33 +00:00
|
|
|
|
|
|
|
- oddbjorn <oddbjorn@tricknology.org>
|