I try with Trex use a pcap file of attack to test the bandwidth of IDS. When I start a yaml script system write me an error:
More than one flow in this cap. Ignoring it !!
ac10850d:ac108bfa:cef0:1540:6:0:0
More than one flow in this cap. Ignoring it !!
4440152c:ac108572:73d:c0a7:11:0:0
More than one flow in this cap. Ignoring it !!
602b9232:ac108552:1bb:ef36:6:0:0
More than one flow in this cap. Ignoring it !!
602b9232:ac108552:1bb:ef38:6:0:0
ERROR packet 38 is not supported, should be Ethernet/IP(0x0800)/(TCP|UDP) format try to convert it using Wireshark !
ERROR reading YAML template files, please verify that they are valid
root@trex:~/v2.22# More than one flow in this cap. Ignoring it !!
More than one flow in this cap. Ignoring it ./t-rex-64 -f ../tss/suricata_bf.yaml -d 60 -m 155
Can I use in Trex pcap files with more then one packet or pcap file must include only one packet?
--
Ilia
--
You received this message because you are subscribed to the Google Groups "TRex Traffic Generator" group.
To unsubscribe from this group and stop receiving emails from it, send an email to trex-tgn+unsubscribe@googlegroups.com.
To post to this group, send email to trex...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/trex-tgn/808f7d77-d5f2-4c47-9171-b1415c467935%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
For attacks we uses Stateless as it has more flexibility (e.g FieldEngine for changing fields etc)
Hanoh