-
Notifications
You must be signed in to change notification settings - Fork 893
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
block ip for service #127
Comments
The procedure to recognize is add a subnet for a range of IP address. but actually, nDPI cannot block a range of IP. |
For block, I convert nDPI in iptables module. But when I use nDPI with NTOP, no traffic is matching with this ip range. |
I checked everything, and the ip range is not categorized. :( |
It's because it's not enough modify only ndpi_content_math.c.inc. |
Thank you !! You will allow me to progress :) |
If you want to add a service, you have to modify two files: the ndpi_content_match.c.inc and the ndpi_protocol_ids.h.
where number is the n+1 number associated to the service you add. Services begin from here: https://github.com/ntop/nDPI/blob/dev/src/include/ndpi_protocol_ids.h#L220 |
I also modified the second file. ndpi_content_match.c.inc :
ndpi_protocol_ids.h :
I have test with URL only, and the traffic is classified. If I test with IP RANGE only, the traffic is not classified. I validated the ip range with tcpdump. What is going on ? |
Can you pass me a pcap with a capture of these packets ? |
See attached file (rename in .pcap) Thank for your help. |
Hi @kYroL01 did you find the problem of my issue ? Thank Adrien |
Hi @adrienb4 sorry for answer you in late. Maybe I'll find the problem, but untill tomorrow i'll busy to work on it. |
@adrienb4 I'm trying to understand the problem. |
@kYroL01 |
But how is classified ? what is the output of nDPI ? |
I give you the classification today. Thank |
For a service, if i not modify the #define NDPI_LAST_IMPLEMENTED_PROTOCOL line, the service is NEVER classified. But it is classified with an increment. For my new tests, i used this configuration :
|
Using nDPI (1.7.1-dev-267-e0c6d80) [1 thread(s)]
|
Ok let me try your configuration and I'll let you know. |
@adrienb4 I think I solved! And also insered the IP range. |
Cool, I expect the solution for my problem :P |
Fixed by bfded90 |
@kYroL01 : Thank for your job. It's work great :) |
@adrienb4 You're welcome :) |
Hi
I would like to create a filter for block 'OCS GO' a french service (similar to NetFlix).
Actualy I can add the website, but what is the procedure for add ip range ?
I add this in 'ndpi_content_math.c.inc, but ips are not matching :
https://apps.db.ripe.net/search/query.html?searchtext=178.248.208.210#resultsAnchor
Thank
Adrien
The text was updated successfully, but these errors were encountered: