Hello, is it possible to ignore certain subnet communication?
My setup:
LAN is
192.168.69.0/24 and
192.168.70.0/24
I want to capture traffic which only leaves and enters my net from/to outside interwebs, ie ignore ALL traffic inside LAN (like NFS between
192.168.69.2 and .69.4)
I feel like it will be something like 'not src net
192.168.69.0/24 and not dst net
192.168.69.0/24', but that does not work - trisul does not start with
Thu Oct 3 14:14:00 2013.394311 FATAL Unable to create processing engine : None of the adapters could be setup
Thu Oct 3 14:14:00 2013.394385 ALERT Error : Pulse Server Failed to initialize, Quitting!
UPD: replaced and with or and 'compiled' BPF with -ddd. Works. Solved.