Re: Log ARP headers

Jeremy Sowden <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
On 2025-03-03, at 21:52:07 +0000, Slavko wrote:
> On 3. marca 2025 19:35:33 UTC, Florian Westphal <[email protected]> wrote:
> > This is only required for logging that is triggered internally,
> > e.g. for nf_conntrack.log_Invalid.
>
> Oh, many thanks, that was not clear for me from any related article.
>
> > I think this is missing support in ulogd2.
> >
> > Untested, to give you some starting point:
> > (3 is NFPROTO_ARP).
> >
> > --- a/filter/raw2packet/ulogd_raw2packet_BASE.c
> > +++ b/filter/raw2packet/ulogd_raw2packet_BASE.c
> > @@ -959,6 +959,8 @@ static int _interp_pkt(struct ulogd_pluginstance *pi)
> >                 return _interp_ipv6hdr(pi, len);
> >         case AF_BRIDGE:
> >                 return _interp_bridge(pi, len);
> > +       case 3:
> > +               return _interp_arp(pi, len);
> >         }
> >         return ULOGD_IRET_OK;
> >  }
>
> Unfortunately, i don't speak C ;-)

I do.

> I understand this change, but i cannot see all consequence,
>
> Any chance that it will go to ulogd itself? Or i have to maintain
> this patch locally only? (I mean for future versions)

I'll look at this when I get a moment.

J.
signature.asc (application/pgp-signature, 931 B)
-----BEGIN PGP SIGNATURE-----

wsG7BAABCgBvBYJnxiaJCRAphqwKvfEEDUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmcj2UbG/biiZ88cfU6jrvwyC2TSYXA91SKsrWg+IfyM
ihYhBGwdtFNj70A3vVbVFymGrAq98QQNAAD0IA/9HJ1DDYOOkXqOOXn0bVYd3CJ+
exCP4wTjtc9VKGxoE95r6Xw+AnlMck+kEaOgoWbYcwl14InqHbZ0anTvpfq/b6i4
bajWOUDL3fLGpwW4ZphtluI9L75+NDaOYeugQeH53zDPrlIf9uoQLmMQZK5TUUcM
MxEJZoo+1iIeIkPj/NoF1V9LSpK67nUNEz8xlpoqRsH1ZYGhATwX1QLA5lcZx8yI
U6HoFm/v0f3My9F003xudhUXw54L9x9SLCJWDuHPJVCuPPt3O/5s4zikmaXkPExT
0WXEC+K1uRUTe2FqdqEcxfeZ5dF3RS/Xq47EzFF7UZUNXm4/lURkTlTxwUmajr4H
WIBopW3QdLuW+AL6DkMuq+jJZ4V1U/Uhd8V0uDsHPm6Tv0h/POfpF3DV+Hr19fg3
Kx2/opFkCZ9gEma6nwL8RkZCuPlmFGUw3PGRfipenwHtd76uFbpu+9mrlpG0wTcZ
8N3yJKSruWdLaUH31d12gGn0S+iRWCzUQGAXEvn7hWPAJELOrrVrmQ6VzLnavMva
4pTa1d0dwQNdzwmTkQ8mY8raQCVdDz9CfWy3WChw+vrw3wmsI1g7/yQMbVdOWnFR
eaAq6XGnVp/w0WoIJvVoMPAxaTBjQh++0QbSPpJ5mQFYZKOv0FJsTGT9jC4fjcCF
t0uVT95vDB3ZHMLVdaQ=
=JaOn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.