<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[TCP Analyser Layered on Ethernet Tap Receives Nothing]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">We're using 5.1.2 with an Ethernet Tap, and we'd like to use the TCP Analyser as a layer on the Ethernet Tap.  However, when we add this layer to the Ethernet tap, we see nothing in the log other than the various messages to do with opening the hardware - no TCP data is logged at all.</p>
<ul>
<li>If we run just the tap without the TCP analyser we see traffic</li>
<li>If we add the TCP analyser as a layer on pcap we see traffic</li>
<li>But if we use TCP Analyser with the Tap, we see nothing.</li>
</ul>
<p dir="auto">We have no filters set.</p>
<p dir="auto">The TX and RX counters are live and incrementing in the Information window.</p>
<p dir="auto">How should we go about diagnosing this?</p>
]]></description><link>http://64.23.185.212/forum/topic/31/tcp-analyser-layered-on-ethernet-tap-receives-nothing</link><generator>RSS for Node</generator><lastBuildDate>Mon, 10 Aug 2026 22:29:00 GMT</lastBuildDate><atom:link href="http://64.23.185.212/forum/topic/31.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 28 Jun 2022 10:07:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Sat, 02 Jul 2022 15:05:07 GMT]]></title><description><![CDATA[<p dir="auto">The issue with adding <strong>TCP/UDP Analyzer</strong> layers via the <em>Layer Pipeline</em> dialog is confirmed. Under these conditions, due to a bug, the <em>filter</em> gets inserted in between the <strong>Ethernet Tap</strong> and <strong>TCP/UDP Analyzer</strong> (instead, it must be attached <em>after</em> <strong>TCP/UDP Analyzer</strong>).</p>
<p dir="auto">The issue will be fixed in the very next release. Meanwhile, you can add these layers by clicking the <em>down</em> arrow next to the <code>Layer Pipeline</code> toolbar button (a button with a <em>plus</em> icon):</p>
<p dir="auto"><img src="/forum/assets/uploads/files/1656774144551-b925e454-b27d-4472-891c-0e05f5f5bd1e-image.png" alt="b925e454-b27d-4472-891c-0e05f5f5bd1e-image.png" class=" img-responsive img-markdown" width="802" height="632" /></p>
<p dir="auto">When added like this, the address filter behaves as expected.</p>
]]></description><link>http://64.23.185.212/forum/post/121</link><guid isPermaLink="true">http://64.23.185.212/forum/post/121</guid><dc:creator><![CDATA[Vladimir]]></dc:creator><pubDate>Sat, 02 Jul 2022 15:05:07 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Fri, 01 Jul 2022 08:42:09 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="http://64.23.185.212/forum/uid/2">@vladimir</a> - thanks for the reply.</p>
<p dir="auto">I just tried it again just now and the filters did work, but I <em>think</em> what's happening is this:</p>
<ul>
<li>If you create a session by selecting Ethernet TAP and adding the TCP Flow Layer at session creation, the filters work</li>
<li>If you create a simple Ethernet TAP session and then later click on the "gear" button and add the TCP Flow Layer, then the filters don't work.  This only really happened because I was adding/removing the TCP layer for testing.</li>
</ul>
<p dir="auto">I'll email you the session because I get a privilege error if I try to add it here.</p>
]]></description><link>http://64.23.185.212/forum/post/120</link><guid isPermaLink="true">http://64.23.185.212/forum/post/120</guid><dc:creator><![CDATA[Will Dean]]></dc:creator><pubDate>Fri, 01 Jul 2022 08:42:09 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Fri, 01 Jul 2022 07:41:04 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Am  I right in thinking that we should be able to enter an IP address OR a TCP port number into that box?</p>
</blockquote>
<p dir="auto">Yes. In that box, you're supposed to enter an IP address with or without a TCP port -- or just a TCP port alone.</p>
<blockquote>
<p dir="auto">Whatever we enter we see no traffic at all.</p>
</blockquote>
<p dir="auto">Hmm, just did a quick test and it seems to work as expected. Could you please share your session (<code>Save</code> -&gt; <code>Save Session</code>, then archive the session folder and attach it to your post) and the filter strings you tried to apply?</p>
<blockquote>
<p dir="auto">BTW, very minor nit, but the placeholder text in the filter box reads "Enter a filter andress...", not "Enter a filter address...".</p>
</blockquote>
<p dir="auto">A typo! Will be fixed.</p>
<p dir="auto">Thank you for your feedback!</p>
]]></description><link>http://64.23.185.212/forum/post/119</link><guid isPermaLink="true">http://64.23.185.212/forum/post/119</guid><dc:creator><![CDATA[Vladimir]]></dc:creator><pubDate>Fri, 01 Jul 2022 07:41:04 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Thu, 30 Jun 2022 13:10:54 GMT]]></title><description><![CDATA[<p dir="auto">Hi Vladimir - many thanks for looking at this for us.   That fix is definitely an improvement in that when we have no filter set, we do now see lots of TCP traffic.</p>
<p dir="auto">But it seems there is a problem with the filter - apparently entering anything into the flow analyser's filter stops us seeing anything.     Am I right in thinking that we should be able to enter an IP address OR a TCP port number into that box?   Whatever we enter we see no traffic at all.</p>
<p dir="auto">BTW, very minor nit, but the placeholder text in the filter box reads "Enter a filter andress...", not "Enter a filter address...".<br />
(There may be better wording anyway if it can also take a port number)</p>
<p dir="auto">Thanks!</p>
]]></description><link>http://64.23.185.212/forum/post/118</link><guid isPermaLink="true">http://64.23.185.212/forum/post/118</guid><dc:creator><![CDATA[Will Dean]]></dc:creator><pubDate>Thu, 30 Jun 2022 13:10:54 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Thu, 30 Jun 2022 12:53:43 GMT]]></title><description><![CDATA[<p dir="auto">BTW the <strong>TX/RX Filter</strong> layer shouldn't have any effect on the <strong>Ethernet Tap</strong> or <strong>Pcap Sniffer</strong> sessions -- as there are no TX/RX data streams there; just the raw Ethernet packets.</p>
<p dir="auto">But after reconstructing TCP or UDP conversations with <strong>TCP/UDP Analyzer</strong>, the <strong>TX/RX Filter</strong> layer can be applied.</p>
]]></description><link>http://64.23.185.212/forum/post/117</link><guid isPermaLink="true">http://64.23.185.212/forum/post/117</guid><dc:creator><![CDATA[Vladimir]]></dc:creator><pubDate>Thu, 30 Jun 2022 12:53:43 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Thu, 30 Jun 2022 12:49:19 GMT]]></title><description><![CDATA[<p dir="auto">Indeed, there's a bug in TCP/UDP analyzer scripts. The fix will be included in the next official release; meanwhile, please use the patch below:</p>
<p dir="auto"><a href="/forum/assets/uploads/files/1656593149975-scripts.7z">scripts.7z</a></p>
<p dir="auto">Simply unpack it overwriting all corresponding <code>*.jnc</code> files. Make sure you <em>overwrite</em> files, not simply unpack it in the <code>scripts</code> folder (thus creating <code>scripts/scripts</code>).</p>
]]></description><link>http://64.23.185.212/forum/post/116</link><guid isPermaLink="true">http://64.23.185.212/forum/post/116</guid><dc:creator><![CDATA[Vladimir]]></dc:creator><pubDate>Thu, 30 Jun 2022 12:49:19 GMT</pubDate></item><item><title><![CDATA[Reply to TCP Analyser Layered on Ethernet Tap Receives Nothing on Tue, 28 Jun 2022 11:29:11 GMT]]></title><description><![CDATA[<p dir="auto">Some more experiments with layering filters onto Ethernet Tap:</p>
<ul>
<li>UDP Flow Analyser is the same as TCP Flow Analyser - nothing is logged</li>
<li>TX/RX Filter layer - the "show Tx/Rx" checkboxes have no effect - everything is logged regardless ( I don't care about this, it was just a test).</li>
</ul>
<p dir="auto">It does seem that we have some general problem with using layers on an Ethernet Tap.</p>
]]></description><link>http://64.23.185.212/forum/post/115</link><guid isPermaLink="true">http://64.23.185.212/forum/post/115</guid><dc:creator><![CDATA[Will Dean]]></dc:creator><pubDate>Tue, 28 Jun 2022 11:29:11 GMT</pubDate></item></channel></rss>