|
OpenBSD Packages and Ports Installation and upgrading of packages and ports on OpenBSD. |
|
Thread Tools | Display Modes |
|
|||
Libpcap installed but no detected
Dear All,
I had installed libpcap-1.7.4 from tcpdump.org into my OpenBSD machine but when I running ./configure command for DAQ packages, it cannot detected the libpcap installation. Why is the error? Error: Code: Checking for pcap_lib_version >= 1.0.0 not found Error: Get it from http://www.tcpdump.org Please help. Thanks. Reference Last edited by Peter_APIIT; 2nd August 2015 at 09:42 AM. |
|
||||
Speaking very generically, you may also be able to tell it where to find the libraries using environment variables. Run
% ./configure --help and look at the bottom of the output. You may see something like this: Code:
Some influential environment variables: CC C compiler command CFLAGS C compiler flags LDFLAGS linker flags, e.g. -L<lib dir> if you have libraries in a nonstandard directory <lib dir> CPPFLAGS C/C++ preprocessor flags, e.g. -I<include dir> if you have headers in a nonstandard directory <include dir> CPP C preprocessor % export LDFLAGS=-L/usr/local/lib or whatever modification of that makes sense for your situation. |
|
|||
Quote:
Code:
./configure make make clean make install When i configure the daq, I also point the libpcap library to the /usr/local/lib/ but it still cannot find it. What should I do now? Thanks a lot. |
|
||||
It's an attempt to port an unexplained application for an unknown purpose. Peter might read this, so I'll explain graphically.
---- Peter, you have a goal. You never ask us the best way to reach it. There are usually multiple paths to the goal. Some may be better than others. We never know the goal you are trying to reach. We are only ever asked about the immediate obstacle. We never know if you are on the wrong path. If you tell us the goal, we might be able to direct you to the correct path. |
|
|||
It appears so, while it's still very much unclear why anyone would ever want to do that.
|
|
|||
OK. Lets me explain it clearly.
I tried to install Snort with IPS configured but Snort packages from OpenBSD repositories does not contain afpacket module. Thus, I install the generic source packages for libpcap, lidnet, daq and snort in order to configure Snort as IPS. Based on Snort documentation, Snort IPS mode is only applicable on Linux with afpacket and not applicable to OpenBSD pf. I think so. Based on this documentation, IPFW in daq modules should be using for inline mode together with pf divert-to. Is this correct? Is it recommend to use Snort inline mode with ipfw daq module in OpenBSD PF? Thanks. Last edited by Peter_APIIT; 4th August 2015 at 03:28 AM. |
|
|||
You need to go back even further. What problem are you experiencing which makes you believe Snort will help resolve?
|
|
|||
Quote:
Edit: Snort also offers preprocessor normalize function. For instance, if TOS was set to non zero value, it will get reset by snort to zero. Last edited by Peter_APIIT; 5th August 2015 at 02:01 AM. |
|
|||
Quote:
|
|
|||
From ftp://ftp.nluug.nl/pub/OpenBSD/5.7/packages/amd64/
Code:
File:snort-2.9.7.0.tgz 3627 KB 03/08/15 14:34:00 File:snort2pf-4.5p0.tgz 9 KB 03/08/15 14:34:00 Quote:
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump Last edited by J65nko; 5th August 2015 at 07:24 AM. |
|
|||
The correct module is ipfw. I wonder how to configure ipfw with snort pf. Thanks.
|
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Triggering pf.conf anchor load based on ip detected | daemonbak | OpenBSD Security | 10 | 27th July 2015 10:43 PM |
5.4 amd64 on Thinkpad x200: "render error detected" on booting. | karl | OpenBSD Installation and Upgrading | 2 | 5th November 2013 04:28 AM |
Partition(s) present but not detected after panic | jb_daefo | FreeBSD General | 0 | 29th May 2009 07:01 PM |
Memory Not Detected | jrs | OpenBSD Installation and Upgrading | 3 | 19th May 2009 05:50 PM |
Installed 4.3 & No GUI | warriors | OpenBSD General | 24 | 14th August 2008 11:28 AM |