# PacketFilter

**URL:** <https://community.zeek.org/t/packetfilter/4730>\
**Category:** Zeek\
**Created:** [March 18, 2017, 5:07pm UTC](https://community.zeek.org/t/packetfilter/4730 "2017-03-18T17:07:39Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 18, 2017, 5:07pm UTC](https://community.zeek.org/t/packetfilter/4730/1 "2017-03-18T17:07:39Z")

</div>

I’m attemtpting to impement a packet filter to drop multicast traffic but I’m not having success.

This is what I have in local.bro:

@load base/frameworks/packet-filter  
redef capture\_filters += {  
[“ip”] = “ip”,  
[“non-ip”] = “not ip”  
};

redef restrict\_filters += { [“not-multicast”] = “net 224.0.0.0/4” };

Which according to the FAQ ([https://www.bro.org/documentation/faq.html](https://www.bro.org/documentation/faq.html)) should produce a BPF like:

((ip) or (not ip)) and (not net 224.0.0.0/4)

But I’m still seeing multicast in the conn log:

1489855468.534667 CM5Ehj4nefU23EOeyj 192.168.20.8 41340 239.254.127.63 60000 udp

It looks like the filters are being implemented:

[BroControl] \> print capture\_filters  
ext-1 capture\_filters = {  
[non-ip] = not ip,  
[ip] = ip  
}

[BroControl] \> print restrict\_filters  
ext-1 restrict\_filters = {  
[not-multicast] = net 224.0.0.0/4  
}

Am I missing a step?

-Dave

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 18, 2017, 5:21pm UTC](https://community.zeek.org/t/packetfilter/4730/2 "2017-03-18T17:21:22Z")

</div>

You could always just add it to your broctl.conf like so:

broargs = --filter 'your bpf here'

James

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 18, 2017, 6:00pm UTC](https://community.zeek.org/t/packetfilter/4730/3 "2017-03-18T18:00:48Z")

</div>

That method worked perfect, thanks James.

I am curious if I was doing something wrong or if PacketFilter is buggy.

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 18, 2017, 6:01pm UTC](https://community.zeek.org/t/packetfilter/4730/4 "2017-03-18T18:01:35Z")

</div>

Damnit. I spoke too soon:

1489860004.749780 C7LM4TvxWGSWhxOL1 192.168.20.8 40972 239.254.127.63 60000

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 18, 2017, 7:20pm UTC](https://community.zeek.org/t/packetfilter/4730/5 "2017-03-18T19:20:06Z")

</div>

tcpdump doesn’t enforce the filter either.

$ sudo tcpdump -nn -i netmap:eth2/Rz not net 224.0.0.0/4 | grep 60000

tcpdump: verbose output suppressed, use -v or -vv for full protocol decode  
listening on netmap:eth2/Rz, link-type EN10MB (Ethernet), capture size 262144 bytes  
15:11:26.286104 IP 192.168.20.8.40364 \> 239.254.127.63.60000: UDP, length 44  
15:11:26.497024 IP 192.168.20.8.47779 \> 239.254.127.63.60000: UDP, length 44  
15:11:26.950899 IP 192.168.20.8.38593 \> 239.254.127.63.60000: UDP, length 44

I’m at a loss now.

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 18, 2017, 7:30pm UTC](https://community.zeek.org/t/packetfilter/4730/6 "2017-03-18T19:30:31Z")

</div>

That’s weird…I can’t reproduce that here…on Ubuntu 16 across the board here. Maybe libpcap or interface issue? My only guess.

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 18, 2017, 7:34pm UTC](https://community.zeek.org/t/packetfilter/4730/7 "2017-03-18T19:34:48Z")

</div>

Thanks for validating James. I’m running netmap + netmap-libpcap and then compiled tcpdump 4.9.0. So looking like a netmap bug.

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 18, 2017, 7:48pm UTC](https://community.zeek.org/t/packetfilter/4730/8 "2017-03-18T19:48:55Z")

</div>

You bet…good luck with the fix…I’d be curious to know what the fix is.

James

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [March 19, 2017, 2:37pm UTC](https://community.zeek.org/t/packetfilter/4730/9 "2017-03-19T14:37:54Z")

</div>

Does tcpdump -ve show any encapsulation like vlans is in use? You may need to use

sudo tcpdump -nn -i netmap:eth2/Rz vlan and not net 224.0.0.0/4

Or it's a bug in netmap 🙂

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 19, 2017, 11:36pm UTC](https://community.zeek.org/t/packetfilter/4730/10 "2017-03-19T23:36:15Z")

</div>

> Does tcpdump -ve show any encapsulation like vlans is in use? You may need to use
> 
> sudo tcpdump -nn -i netmap:eth2/Rz vlan and not net 224.0.0.0/4
> 
> Or it’s a bug in netmap 🙂
> 
> –
> 
> - Justin Azoff

I built a new Bro cluster without Netmap (standard libpcap-dev libraries for Debian 8.7) and the BPF works as expected:

$ sudo tcpdump -nn -i eth2 net 224.0.0.0/4 | grep 60000  
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode  
listening on eth2, link-type EN10MB (Ethernet), capture size 262144 bytes

14:38:37.656784 IP 192.168.20.4.34697 \> 239.254.127.63.60000: UDP, length 44  
14:38:37.656799 IP 192.168.20.4.34697 \> 239.254.127.63.60000: UDP, length 44  
14:38:37.656974 IP 192.168.20.4.45799 \> 239.254.127.63.60000: UDP, length 44

AND

$ sudo tcpdump -nn -i eth2 not net 224.0.0.0/4 | grep 60000  
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode  
listening on eth2, link-type EN10MB (Ethernet), capture size 262144 bytes

4866 packets received by filter  
0 packets dropped by kernel

-Dave

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 19, 2017, 11:46pm UTC](https://community.zeek.org/t/packetfilter/4730/11 "2017-03-19T23:46:53Z")

</div>

And there you go…I think I attempted netmap a couple months ago…didn’t have good results, so stuck with af\_packet. Looks like netmap needs a massage.

James

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [March 20, 2017, 7:16pm UTC](https://community.zeek.org/t/packetfilter/4730/12 "2017-03-20T19:16:45Z")

</div>

Could you try using the netmap plugin for Bro instead of the modified libpcap? The filtering should work correctly there.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [March 20, 2017, 9:27pm UTC](https://community.zeek.org/t/packetfilter/4730/13 "2017-03-20T21:27:39Z")

</div>

Sure, I’ll uninstall netmap-libpcap, install the standard Debian libpcap-dev and recompile Bro. Will respond back with observations.

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [March 21, 2017, 2:45am UTC](https://community.zeek.org/t/packetfilter/4730/14 "2017-03-21T02:45:27Z")

</div>

You don’t need to do that if you don’t want to. Just compile and install the netmap plugin that ships with Bro 2.5. Check out the README that comes with it too because it explains how to configure a cluster with the netmap plugin.

.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/packetfilter/4730/15 "2022-05-06T15:44:45Z")

</div>


