From: Stefan Keller <sk@open.ch>
To: jean-philippe.menil@univ-nantes.fr
Cc: netfilter@vger.kernel.org
Subject: Re: Virtual packet tracer for iptables
Date: Fri, 08 Jun 2012 15:36:49 +0200 [thread overview]
Message-ID: <4FD1FFF1.1080604@open.ch> (raw)
In-Reply-To: <4FD1F728.8050107@univ-nantes.fr>
> But you do not have to enable TRACE for all your sessions, only
> the informations you are looking for.
Hi,
Yes, that's true, TRACE does not have to be enabled for all sessions.
But with TRACE I rely on real traffic and there is some interaction
necessary to create such traffic (if multiple parties are involved).
The idea I have is a bit the same as with routing. If I want to know
where a packet is routed to, then I use 'ip route get <dst_ip>' and
can even add other information such as incoming interface, source IP
address, FWMARK, etc. to consider my routing policy.
I don't wait or look for traffic that matches my requirements and
check with tcpdump where it is routed to - I ask the system for the
action based on my input.
It would be great to have a similar mechanism with iptables.
Best regards
Stefan Keller
--
stefan keller
product manager
open systems ag
raeffelstrasse 29
ch-8045 zurich
t: +41 44 455 74 00
f: +44 44 455 74 01
stefan.keller@open.ch
http://www.open.ch
prev parent reply other threads:[~2012-06-08 13:36 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-06-08 11:32 Virtual packet tracer for iptables Stefan Keller
2012-06-08 11:56 ` Jean-Philippe Menil
2012-06-08 12:33 ` Stefan Keller
2012-06-08 12:59 ` Jean-Philippe Menil
2012-06-08 13:36 ` Stefan Keller [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FD1FFF1.1080604@open.ch \
--to=sk@open.ch \
--cc=jean-philippe.menil@univ-nantes.fr \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.