From owner-freebsd-current@FreeBSD.ORG Thu Jan 22 21:02:42 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 75B7916A4CE; Thu, 22 Jan 2004 21:02:42 -0800 (PST) Received: from fep02-mail.bloor.is.net.cable.rogers.com (fep02-mail.bloor.is.net.cable.rogers.com [66.185.86.72]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0096243D41; Thu, 22 Jan 2004 21:02:41 -0800 (PST) (envelope-from vchekan@rogers.com) Received: from CPE000ae698217d-CM000a739a9e0a.cpe.net.cable.rogers.com fep02-mail.bloor.is.net.cable.rogers.comESMTP <20040123050032.CIZE116070.fep02-mail.bloor.is.net.cable.rogers.com@CPE000ae698217d-CM000a739a9e0a.cpe.net.cable.rogers.com>; Fri, 23 Jan 2004 00:00:32 -0500 From: Vadim Chekan To: phk@FreeBSD.org Date: Fri, 23 Jan 2004 00:02:18 +0000 User-Agent: KMail/1.5.4 MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200401230002.18543.vchekan@rogers.com> X-Authentication-Info: Submitted using SMTP AUTH PLAIN at fep02-mail.bloor.is.net.cable.rogers.com from [67.60.165.184] using ID at Fri, 23 Jan 2004 00:00:32 -0500 cc: freebsd-current@freebsd.org Subject: JKH: tcpdump improvement X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Jan 2004 05:02:42 -0000 Hello Poul, I want to try to implement portrange feature in tcpdump as described on your JKH TODO list if it's still actual. I have several thoughts about this task. 1. As soon as it is neccessary to implement portN to implement this task it is a good idea to extend syntax with these operators. Actually after implementing "<" and ">" operators task is 80% done because it is possible to implement range by "port > N1 and port < N2" expression. 2. About range operator. I'd prefer to add functionality to existing "port" operator instead of introducing new keyword "portrange". It seems easier to remember and use syntax like: "port 40-400 and port 500" What do you think? Thanks Vadim Chekan.