Possible bug with Argus-2.0.6-beta5?

Andrew.hall temp02 at bluereef.com.au
Sun Jan 12 20:50:15 EST 2003


Hi,

I have just downloaded and built 2.0.6-beta5 with no compile problems. When
trying to run the following command:

./argus_linux -d -B 127.0.0.1 -P 561 -S 10 -i eth1 -i eth0 - '((src net
10.1.1 and ! dst net 10.1.1) or (! src net 10.1.1 and dst net 10.1.1))'

argus fails to run. Instead it dumps what looks like a decimal version of
the filter compiler output for the above filter string and then stops. The
issue seems to be that it doesn't like two interfaces given on the command
line. One works fine. Is this correct? From what  I've read Argus supports
multiple interfaces? I haven't been using argus for long so it maybe an
issue with my understanding of how argus works.

Also a couple of other questions please:

1. Exactly how many interfaces will argus listen to under linux 2.4 (one
argus process only)?
2. If configured to listen to more than one interface and the traffic passes
through the argus probe (in one interface and out the other) will argus
report duplicate entries for packet flows? If so is there some way to
identify and stop these duplicates?

thanks and regards,

Andrew.



More information about the argus mailing list