diff --git a/doc/windivert.html b/doc/windivert.html index a03633f..1315b59 100644 --- a/doc/windivert.html +++ b/doc/windivert.html @@ -104,10 +104,8 @@ This will build the following files and place them in the install\WDDK subdirectory: @@ -119,10 +117,9 @@ See below for Visual Studio 2012 and MinGW support.

2.1 Driver Signing

-Before the WinDivert package can be used, the WinDivert.sys driver -must contain a valid digital signature. -This is Microsoft policy for all kernel drivers in recent versions of -Windows. +Before the WinDivert package can be used, the +WinDivert32.sys/WinDivert64.sys driver +must be digitally signed. See Driver Signing Requirements for Windows for more information.

@@ -164,30 +161,134 @@ This will build MinGW compatible files and place them in the

3. Installing

WinDivert does not require any special installation. -Simply place the WinDivert.dll, WinDivert.sys, -WinDivert.inf, and WdfCoInstaller*.dll files in the -application's home directory. +Depending on your target configuration, simply place the following files in +your application's home directory: +

+
+ + + + + + + + + + + + + + + + + + + + + +
+Application Type + +Target Windows Type + +Files Required +
+32-bit + +32-bit Windows only + +WinDivert.dll (32-bit version) and WinDivert32.sys +
+64-bit + +64-bit Windows only + +WinDivert.dll (64-bit version) and WinDivert64.sys +
+32-bit + +Both 32-bit and 64-bit Windows + +WinDivert.dll (32-bit version), WinDivert32.sys, + and WinDivert64.sys +
+
+

+The WinDivert driver is automatically (and silently) installed on demand +whenever your application calls +WinDivertOpen(). +The calling application must have Administrator privileges.

-The WinDivert driver is automatically installed on demand whenever your -application calls WinDivertOpen(). -The driver installation is also silent. -The calling application must be running with Administrator privileges. +The WinDivert.dll also depends on a C run-time library. +This is not distributed with the WinDivert binaries, and must be +installed/distributed separately if required.

+
+ + + + + + + + + + + + + + + + + + + + + +
+Build/Compiler + +C-Runtime Dependency + +Installed on Windows by Default? +
+WDDK (Windows Driver Kit 7.1) + +MSVCRT.dll + +Yes +
+MSVC (Visual Studio 2012) + +MSVCRT110.dll + +No. +Must be installed separately or included with your application. +
+MINGW + +MSVCRT.dll + +Yes +
+

4. Uninstalling

-To uninstall, simply delete the WinDivert.dll, WinDivert.sys, -WinDivert.inf, and WdfCoInstaller*.dll files. -The WinDivert driver is silently uninstalled when the calling application -terminates or unloads the WinDivert.dll library. -The WinDivert driver can also be removed manually by issuing the following +To uninstall, simply delete the WinDivert.dll, +WinDivert32.sys, and WinDivert64.sys files. +If already running, the WinDivert driver will be automatically +uninstalled during the next machine reboot. +The WinDivert driver can also be manually removed by issuing the following commands at the command prompt

 sc stop WinDivert1.1
 sc delete WinDivert1.1
 
+Note that this is not recommended as it will interfere with other +applications that depend on WinDivert.


@@ -286,9 +387,9 @@ Description 2 -One or more of the WinDivert.sys, -WinDivert.inf, or WdfCoInstaller*.dll files were not -found. +The driver files +WinDivert32.sys or WinDivert64.sys +were not found. @@ -321,7 +422,8 @@ This indicates an invalid packet filter string, layer, priority, or flags. 577 -The WinDivert.sys driver does not have a valid digital signature +The WinDivert32.sys or WinDivert64.sys driver does not +have a valid digital signature (see the driver signing requirements above). @@ -335,9 +437,7 @@ The WinDivert.sys driver does not have a valid digital signature This error occurs for various reasons, including:
    -
  1. attempting to load the 32-bit WinDivert.sys driver on a 64-bit -system (or vice versa);
  2. -
  3. the WinDivert.sys driver is blocked by security software; or +
  4. the WinDivert driver is blocked by security software; or
  5. you are using a virtualization environment that does not support drivers.
@@ -1396,14 +1496,16 @@ They are
  • Injecting inbound ICMP/ICMPv6 messages: For some ICMP/ICMPv6 messages, inbound injection does not work. An error will be returned and the packet will be lost. - It is suspected that this is an issue with the WFP framework on which - WinDivert is built. The work-around is to inject inbound ICMP messages as outbound.
  • No IPv6 extension header support: Currently there is no filter support for IPv6 packets with extension headers. The work around is to capture all IPv6 traffic.
  • +
  • The forward layer does not interact well with the Windows NAT: + It is not possible to block packets pre-NAT with WinDivert. + As a general principle, you should not try and mix WinDivert at the + forward layer with the Windows NAT implementation.