Closed jsturtevant closed 2 years ago
looks like verification of ELF file passed:
netsh ebpf show verification conn_track.o sockops level=verbose
Verification succeeded
Program terminates within 545 instructions
and sys file has sections:
PS C:\Users\User\ebpf-for-windows-demo\x64\Release> netsh ebpf show sections .\conn_track.sys
Size
Section Type (bytes)
==================== ========= =======
sockops sockops 4684
Key Value Max
Map Type Size Size Entries Name
================== ==== ===== ======= ========
lru_hash 56 8 1024 connection_map
ringbuf 0 0 262144 history_map
running the following shows that ebpf isn't running
sc query ebpfcore
sc query netebpfext
Starting them manually with:
net start netebpfext
net start ebpfcore
net start ebpfsvc
and the demo works!
after going through https://github.com/microsoft/ebpf-for-windows-demo/blob/main/connection_tracker/README.md#demo-steps on a windows 11 machine with eBFP-for-windows (v0.4.0) installed I get: