Re: ndpi with ntop

2014-05-05 Thread Destan YILANCI
You can use Snort Alpha + ipfw daq + OpenAppId to block applications via divert sockets. But dont forget it is experimental for now and i can not say it is working well... -- Destan YILANCI 5 May 2014 tarihinde 15:21 saatinde, Richard Thornton şunları yazdı: > Hi, > > Does anybody know of a

Re: ndpi with ntop

2014-05-05 Thread Franco Fichtner
Hi Richard, On 05 May 2014, at 14:21, Richard Thornton wrote: > Does anybody know of any integration between PF and ndpi? the previous consensus[1] was that pf(4) and DPI do not mix very well, but you can probably use relayd(8) and run e.g. NDPI on top[2]. Grabbing all traffic is not really fa

ndpi with ntop

2014-05-05 Thread Richard Thornton
Hi, Does anybody know of any integration between PF and ndpi? I would love to be able to block by application (bittorrent, skype...) in PF! If there is nothing out there, would it be a lot of work, is ndpi already working in OpenBSD? Thanks. Richard