* iptables log Len ?
@ 2004-01-29 2:07 Michael Gale
2004-01-29 2:58 ` William Stearns
0 siblings, 1 reply; 2+ messages in thread
From: Michael Gale @ 2004-01-29 2:07 UTC (permalink / raw)
To: netfilter
Hello,
When you log a packet entry one of the fields is Len (example Len=78). Now does this mean the was
was 78 bytes ?
--
Michael Gale
Network Administrator
Utilitran Corporation
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: iptables log Len ?
2004-01-29 2:07 iptables log Len ? Michael Gale
@ 2004-01-29 2:58 ` William Stearns
0 siblings, 0 replies; 2+ messages in thread
From: William Stearns @ 2004-01-29 2:58 UTC (permalink / raw)
To: Michael Gale; +Cc: ML-netfilter, William Stearns
Good evening, Michael,
On Wed, 28 Jan 2004, Michael Gale wrote:
> When you log a packet entry one of the fields is Len (example
> Len=78). Now does this mean the was was 78 bytes ?
Yes, the first LEN on the line is the length of the IP header, TCP
header, and payload. Some packets have 2 LEN tokens, I believe the second
is TCP header + payload. For ICMP error messages where the original
packet decode is inside [...], the LEN inside the square brackets is the
length of the packet that elicited the error.
Cheers,
- Bill
---------------------------------------------------------------------------
"Whip me, beat me, make me use ipchains."
- Paul "Rusty" Russell
--------------------------------------------------------------------------
William Stearns (wstearns@pobox.com). Mason, Buildkernel, freedups, p0f,
rsync-backup, ssh-keyinstall, dns-check, more at: http://www.stearns.org
--------------------------------------------------------------------------
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2004-01-29 2:58 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-01-29 2:07 iptables log Len ? Michael Gale
2004-01-29 2:58 ` William Stearns
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox