From mboxrd@z Thu Jan 1 00:00:00 1970 Message-ID: <4B323EE8.6000206@pandora.be> Date: Wed, 23 Dec 2009 17:01:44 +0100 From: Bart De Schuymer MIME-Version: 1.0 References: <00163600ce448e8674047b65d7bf@google.com> In-Reply-To: <00163600ce448e8674047b65d7bf@google.com> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Subject: Re: [Bridge] Re :Re: ebtables, PF_PACKET and other stuff List-Id: Linux Ethernet Bridging List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: jhautbois@gmail.com Cc: bridge@lists.linux-foundation.org jhautbois@gmail.com schreef: >> Send those packets to the ULOG target when dropping them. > > > >> From the ebtables manpage: > > > >> ulog > > > >> The ulog watcher passes the packet to a userspace logging daemon using > >> netlink multicast sockets. This differs from the log watcher in the > >> sense that the complete packet is sent to userspace instead of a > >> descriptive text and that netlink multicast sockets are used instead > >> of the syslog. This watcher enables parsing of packets with userspace > >> programs > >> (snip) > > Mmh, ok, but from the userspace point of view, how can I get them ? A > SOCK_RAW ? > See http://ebtables.sourceforge.net/examples/basic.html#ex_ulog cheers, Bart -- Bart De Schuymer www.artinalgorithms.be