mirror of
https://github.com/pi-hole/docs.git
synced 2024-12-06 19:27:12 +01:00
FTL internal package dump (#638)
* FTL internal package dump Signed-off-by: Christian König <ckoenig@posteo.de> * Shorten name Signed-off-by: Christian König <ckoenig@posteo.de> * Restructure FTL menu Signed-off-by: Christian König <ckoenig@posteo.de>
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
## Pi-hole FTL's internal pcap packet dump
|
||||
|
||||
Pi-hole has its own embedded package dumping. It can be enabled by adding the following to a file like `/etc/dnsmasq.d/99-record.conf`:
|
||||
|
||||
```
|
||||
dumpfile=/etc/pihole/dump.pcap
|
||||
```
|
||||
|
||||
(or any other location you prefer), in addition to
|
||||
|
||||
```
|
||||
dumpmask=<mask>
|
||||
```
|
||||
|
||||
where `mask` specifies which types of packets should be added to the dumpfile defined above. The argument should be the OR of the bitmasks for each type of packet to be dumped: it can be specified in hex by preceding the number with 0x in the normal way.
|
||||
Each time a packet is written to the dumpfile, we log the packet sequence and the mask representing its type. The current types are:
|
||||
|
||||
- `0x0001` - DNS queries from clients
|
||||
- `0x0002` - DNS replies to clients
|
||||
- `0x0004` - DNS queries to upstream
|
||||
- `0x0008` - DNS replies from upstream
|
||||
- `0x0010` - queries send upstream for DNSSEC validation
|
||||
- `0x0020` - replies to queries for DNSSEC validation
|
||||
- `0x0040` - replies to client queries which fail DNSSEC validation
|
||||
- `0x0080` - replies to queries for DNSSEC validation which fail validation.
|
||||
|
||||
If you just want to record everything and later filter this in Wireshark you can just add the two lines
|
||||
|
||||
```
|
||||
dumpfile=/etc/pihole/dump.pcap
|
||||
dumpmask=0x00ff
|
||||
```
|
||||
|
||||
{!abbreviations.md!}
|
||||
+10
-8
@@ -108,16 +108,18 @@ nav:
|
||||
- 'DNS cache': ftldns/dns-cache.md
|
||||
- 'Blocking mode': ftldns/blockingmode.md
|
||||
- 'Privacy levels': ftldns/privacylevels.md
|
||||
- 'Telnet API': ftldns/telnet-api.md
|
||||
- 'Signals': 'ftldns/signals.md'
|
||||
- 'Compatibility': ftldns/compatibility.md
|
||||
- 'Install from source': ftldns/compile.md
|
||||
- 'dnsmasq warnings': ftldns/dnsmasq_warn.md
|
||||
- 'Cache dump': ftldns/cache_dump.md
|
||||
- 'Debugging FTLDNS':
|
||||
- 'gdb': ftldns/debugging.md
|
||||
- 'valgrind': ftldns/valgrind.md
|
||||
- 'In-depth manual': ftldns/in-depth.md
|
||||
- 'Advanced':
|
||||
- 'Install from source': ftldns/compile.md
|
||||
- 'Telnet API': ftldns/telnet-api.md
|
||||
- 'Signals': 'ftldns/signals.md'
|
||||
- 'Cache dump': ftldns/cache_dump.md
|
||||
- 'Packet dump': ftldns/package_dump.md
|
||||
- 'Debugging':
|
||||
- 'gdb': ftldns/debugging.md
|
||||
- 'valgrind': ftldns/valgrind.md
|
||||
- 'In-depth manual': ftldns/in-depth.md
|
||||
- 'RegEx blocking':
|
||||
- "Overview": regex/overview.md
|
||||
- "Testing": regex/testmode.md
|
||||
|
||||
Reference in New Issue
Block a user