From: "Eric Poulin" <epoulin@onepost.net>
To: netfilter@lists.netfilter.org
Subject: Re: MAC Addresses in Logfile Entries
Date: Tue, 22 Apr 2003 22:13:25 -0400 [thread overview]
Message-ID: <003401c3093d$ec896c30$0200a8c0@storm> (raw)
In-Reply-To: 200304230107.h3N17N5c024243@osprey.tkevans.com
> Some of our log entries contain MAC addresses, like this:
> Apr 20 10:15:35 foo kernel: IPT IN_FIREWALL: IN=eth1 OUT=
> MAC=00:30:48:11:94:e5:00:d0:ba:45:ec:25:08:00 SRC=XXX.XX.XX.XX
> DST=XXX.XX.XX.XX LEN=40 TOS=0x00 PREC=0x00 TTL=48 ID=0 DF PROTO=TCP
> SPT=1572 DPT=1080 WINDOW=32430 RES=0x00 SYN URGP=0
> While others don't:
> Apr 14 07:55:35 foo kernel: IPT FORWARD: IN=eth0 OUT=eth1
> SRC=XXX.XX.XX.XX DST=XXX.XX.XX.XX LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=225
> DF PROTO=TCP SPT=1047 DPT=37 WINDOW=64512 RES=0x00 SYN URGP=0
>
> I see the "OUT" field in the latter contains "eth1" instead of a MAC
> address.
>
> Can someone elaborate on the difference here? Thanks.
I'm experiencing this bahavior for a while already, and from what I can see,
I will only see the MAC address in the log ONLY if the packet was destinated
for the local machine(Or was generated BY the machine), but I will never see
MACs if the packet logged was for another machine than the firewall.
If somebody can confirm...
Eric Poulin
next prev parent reply other threads:[~2003-04-23 2:13 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-04-23 1:07 MAC Addresses in Logfile Entries Tim Evans
2003-04-23 2:13 ` Eric Poulin [this message]
2003-04-23 5:19 ` Bjorn Ruberg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='003401c3093d$ec896c30$0200a8c0@storm' \
--to=epoulin@onepost.net \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.