Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Alistair Tonner <Alistair@nerdnet.ca>
To: netfilter@lists.netfilter.org
Subject: Re: Logging MAC
Date: Sat, 22 May 2004 08:09:47 -0400	[thread overview]
Message-ID: <200405220809.47858.Alistair@nerdnet.ca> (raw)
In-Reply-To: <200405221006.14904.Antony@Soft-Solutions.co.uk>

On May 22, 2004 05:06 am, Antony Stone wrote:
> On Saturday 22 May 2004 2:47 am, Alistair Tonner wrote:
> > 	I note that iptables doesn't log mac addresses it cannot see (i.e. not
> > directly connected) ... in 1.2.9x (as I and Antony are running) you still
> > see the MAC= element.  Perhaps in CVS the logging function drops this
> > entry if MAC="" ??
>
> Surely there will *always* be two MAC addresses involved in a communication
> - that's how two machines find each other across the local subnet (ie: via
> a switch / hub / access point etc)?

	*Thwack*'s self in head.  Of course, so long as "Ethernet" is involved.  Not 
being 100% on the ball at that moment, I was looking at lines from my ppp 
connection which is pppoe in reality. -- There is no 'ethernet' frame 
involved on that link, thus there are no 'MAC' addresses, or at least there 
aren't MAC addresses in the ppp packets, the MAC address is in the wrapping 
ethernet frame which is going through a dfferent device, which is either 
before or after the ppp device, depending on direction.

>
> I agree that in a multi-hop connection between systems, at least one of the
> MAC addresses seen by netfilter will definitely not be an endpoint (it will
> be an interface on a local router), however unless you are running an
> access point *as* a router (the standard way to run them is as a bridge)
> then you should still see the MAC address of whatever machine is talking to
> the firewall?
  
	Ummm .. I don't think so:	
	in ipt_LOG.c MAC address logging is ONLY done in INPUT.  So ..if the
	packet is NOT destined for the machine, you wont see MAC.

>
> > -- that would indicate that someone on the wireless is being
> > hijacked as a proxy?? *ugh*
>
> In which case you would see the MAC address of the hijacked poxy machine...
	
>
> Regards,
>
> Antony.


  reply	other threads:[~2004-05-22 12:09 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-05-21 13:39 Logging MAC Marcelus Trojahn
2004-05-21 13:53 ` Antony Stone
2004-05-21 14:17   ` Re[2]: " Marcelus Trojahn
2004-05-21 14:34     ` Antony Stone
2004-05-21 15:07       ` Re[4]: " Marcelus Trojahn
2004-05-21 15:25         ` Antony Stone
2004-05-22  1:47           ` Alistair Tonner
2004-05-22  9:06             ` Antony Stone
2004-05-22 12:09               ` Alistair Tonner [this message]
2004-05-22 12:33                 ` Antony Stone
2004-05-22 15:57                   ` Alistair Tonner
2004-05-22 16:17                     ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200405220809.47858.Alistair@nerdnet.ca \
    --to=alistair@nerdnet.ca \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox