Linux Netfilter discussions
 help / color / mirror / Atom feed
* Cloning Traffic had having it processed by two different hosts - TEE
@ 2008-04-23 12:24 Bjoern Weiland
  2008-04-23 15:07 ` Jan Engelhardt
  2008-04-23 19:40 ` Grant Taylor
  0 siblings, 2 replies; 4+ messages in thread
From: Bjoern Weiland @ 2008-04-23 12:24 UTC (permalink / raw)
  To: netfilter

Hey list,

here's what I need to do:
Our central routers all export cisco netflow data. This data is being 
sent to HOST A where it is processed. Now for some researching, I also 
need this data on HOST B for another kind of processing. So what I want 
to do is to clone the traffic arriving at HOST A. One copy should be 
processed by HOST A as usual and the copy needs to be sent to HOST B. As 
we do not only want to passively monitor this traffic, but really work 
with it, the copied traffic also needs to be rewritten with HOST B's IP 
address in the netflow data's Headers.

No here's the question: How do I best do this? I read and tried to work 
with the tee target of patch-o-matic-ng's extra repository, but 
apparently it is not working any longer on recent kernels.
Also I do have massive problems getting xtables-addons to compile on my 
Debian (I actually tried more than one machine and different gcc's and 
kernels) and there seems to be no documentation or mailinglist. Has 
anyone tried xtables-addons at Debian? If yes, which gcc, kernel, 
xtables version?

Now I am wondering, if my undertaking is realizable and how it can be 
done most efficiently... I am open for any hints, maybe there are some 
other solutions as well...

  -best regards, bjoern

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2008-04-24 13:21 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-04-23 12:24 Cloning Traffic had having it processed by two different hosts - TEE Bjoern Weiland
2008-04-23 15:07 ` Jan Engelhardt
2008-04-24 13:21   ` Bjoern Weiland
2008-04-23 19:40 ` Grant Taylor

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox