From: Alistair Tonner <Alistair@nerdnet.ca>
To: netfilter@lists.netfilter.org
Subject: Re: Logging MAC
Date: Sat, 22 May 2004 08:09:47 -0400 [thread overview]
Message-ID: <200405220809.47858.Alistair@nerdnet.ca> (raw)
In-Reply-To: <200405221006.14904.Antony@Soft-Solutions.co.uk>
On May 22, 2004 05:06 am, Antony Stone wrote:
> On Saturday 22 May 2004 2:47 am, Alistair Tonner wrote:
> > I note that iptables doesn't log mac addresses it cannot see (i.e. not
> > directly connected) ... in 1.2.9x (as I and Antony are running) you still
> > see the MAC= element. Perhaps in CVS the logging function drops this
> > entry if MAC="" ??
>
> Surely there will *always* be two MAC addresses involved in a communication
> - that's how two machines find each other across the local subnet (ie: via
> a switch / hub / access point etc)?
*Thwack*'s self in head. Of course, so long as "Ethernet" is involved. Not
being 100% on the ball at that moment, I was looking at lines from my ppp
connection which is pppoe in reality. -- There is no 'ethernet' frame
involved on that link, thus there are no 'MAC' addresses, or at least there
aren't MAC addresses in the ppp packets, the MAC address is in the wrapping
ethernet frame which is going through a dfferent device, which is either
before or after the ppp device, depending on direction.
>
> I agree that in a multi-hop connection between systems, at least one of the
> MAC addresses seen by netfilter will definitely not be an endpoint (it will
> be an interface on a local router), however unless you are running an
> access point *as* a router (the standard way to run them is as a bridge)
> then you should still see the MAC address of whatever machine is talking to
> the firewall?
Ummm .. I don't think so:
in ipt_LOG.c MAC address logging is ONLY done in INPUT. So ..if the
packet is NOT destined for the machine, you wont see MAC.
>
> > -- that would indicate that someone on the wireless is being
> > hijacked as a proxy?? *ugh*
>
> In which case you would see the MAC address of the hijacked poxy machine...
>
> Regards,
>
> Antony.
next prev parent reply other threads:[~2004-05-22 12:09 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-05-21 13:39 Logging MAC Marcelus Trojahn
2004-05-21 13:53 ` Antony Stone
2004-05-21 14:17 ` Re[2]: " Marcelus Trojahn
2004-05-21 14:34 ` Antony Stone
2004-05-21 15:07 ` Re[4]: " Marcelus Trojahn
2004-05-21 15:25 ` Antony Stone
2004-05-22 1:47 ` Alistair Tonner
2004-05-22 9:06 ` Antony Stone
2004-05-22 12:09 ` Alistair Tonner [this message]
2004-05-22 12:33 ` Antony Stone
2004-05-22 15:57 ` Alistair Tonner
2004-05-22 16:17 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200405220809.47858.Alistair@nerdnet.ca \
--to=alistair@nerdnet.ca \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox