Re: passing packet to user space

Darren Reed <[email protected]> Mon, 27 Jul 2009 11:45:43 -0700
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <20135_1248720518_4A6DF686_20135_6787_1_4A6DF5D7.7060003@reed.wattle.id.au>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Scott Mann wrote:
| Hi,
|
| I need to be able to capture an entire packet and pass it to a user 
space application for manipulation of the data header. It seems that 
such functionality does not exist in ipfilter, is that correct? I need 
to do this for Solaris 10/OpenSolaris. Any pointers as to where I should 
start to incorporate this capability? Or should I write a separate 
Solaris kernel module?

IPFilter only supports copying header information to user space,
the application can only return a "yes/no", it cannot change the
header or packet data in any way.

Darren


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
 
iEYEARECAAYFAkpt9dcACgkQP7JIXtvLbFXFmwCgx6ehOQC/NuFbLgMod7EFk7Z2
xO0AoLnzElmu/VOy2x0ohqdlsdyi3J3f
=Baau
-----END PGP SIGNATURE-----