Linux Netfilter discussions
 help / color / mirror / Atom feed
* ULOG/NFLOG on a non-forwarding machine
@ 2008-09-23  9:50 Benny Amorsen
  2008-09-24  2:57 ` Grant Taylor
  2008-09-26  0:43 ` Philip Craig
  0 siblings, 2 replies; 7+ messages in thread
From: Benny Amorsen @ 2008-09-23  9:50 UTC (permalink / raw)
  To: netfilter

We have a monitor server in place which we use to get flow
information. Currently libpcap-based is in use, but it would be nice
to be able to use ULOG or NFLOG for this.

The challenge is that the monitor-server does not actually forward any
packets. It is connected to a mirror-port on a switch, so that it is
able to see all traffic. However, the traffic does not show up in any
netfilter chains, because no routing or bridging is in place on the
monitor server.

Is there a way to catch incoming traffic which is neither INPUT nor
FORWARD with netfilter?


/Benny



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-10-02  8:44 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-09-23  9:50 ULOG/NFLOG on a non-forwarding machine Benny Amorsen
2008-09-24  2:57 ` Grant Taylor
2008-09-25  9:07   ` Benny Amorsen
2008-09-25 14:05     ` Grant Taylor
2008-09-26  0:43 ` Philip Craig
2008-09-27 13:42   ` Benny Amorsen
2008-10-02  8:44   ` Покотиленко Костик

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox