Hi Bowen the nbpf syntax actually supports the not operator, however it depends on the actual backend (we probably need to extend the guide commenting more about this). For instance translating the filter into hw rules for offloading it to the adapter, in most cases it is not possible to use the not operator. What is your use case/application/card where you are using nbpf?
Regards Alfredo > On 27 Jun 2018, at 04:48, Bowen Li <[email protected]> wrote: > > Hi all, > The README of ndpf section in github notes that “NOT” cannot be used as > keyword in filter, however, I used “NOT” and the filter is effective in my > test process. I want to know if there is something wrong in the official > documents or I omitted anything in my code. > If the used format of filter is “not host A and not host B and...”, how > many hosts that ndpf could support to filter in maximum? Besides, could you > please tell me if pcap processing speed of PF_RING will be influenced with > the increase of filter length? > Any insight would be helpful. > _______________________________________________ > Ntop-misc mailing list > [email protected] > http://listgateway.unipi.it/mailman/listinfo/ntop-misc
signature.asc
Description: Message signed with OpenPGP
_______________________________________________ Ntop-misc mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop-misc
