15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

src for example is defined as ip_src. ip_src is defined as [12, b] in the included tcpip.def.<br />

tcpip.def can be found in $FWDIR/lib and is a very good resource for <strong>use</strong>ful definitions. You can<br />

include other files in $FWDIR/lib as well if you like.<br />

If you <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r you can create your own “library” and include it (e.g. using the –f option). This<br />

allows you <strong>to</strong> define your own definitions of commands and expressions you are using on a regular basis.<br />

Take a look at Useful macros in tcpip.def for a collection of <strong>use</strong>ful expressions.<br />

! Please note that predefined macros (like src, dport, sport …) are only au<strong>to</strong>matically defined if<br />

you are using expressions on the command line. If you are using files or standard input for providing<br />

filter expressions you have <strong>to</strong> define the macros for yourself or include them using the #include<br />

directive manually.<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 37 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!