On 21 Aug, Ruslan Ermilov wrote: > On Fri, Aug 20, 2004 at 11:07:34PM +0300, Maxim Sobolev wrote: >> Andrew Gallatin wrote: >> >You're almost certainly using a driver which offloads transmit >> >checksums. (both fxp and em do) Since BPF sniffs the packet before it >> >leaves the host, the checksum has not yet been calculated, so it looks >> >bad. >> >> Is it possible to detect this situation and flag tcpdump somehow, so >> that it don't trust checksum? With the widespread adoption of GigE >> cards, this "problem" is likely to be more and more common. >> > It's easy to detect using the m_pkthdr.csum_flags. It shouldn't > be impossible to make a writable mbuf chain copy, and call > in_delayed_cksum() on a copy, before calling bpf_mtap(). >From a performance point of view, you'd probably want defer calculating the checksum until after the packet has passed the BPF filter, otherwise you'd consume an excessive amount of CPU time when sniffing for infrequently occurring packets on a high bandwidth network interface.Received on Fri Aug 20 2004 - 20:49:51 UTC
This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:07 UTC