PROBE::NETFILTER\&.A
Section: Networking Tapset (3stap)
Updated: November 2020
Page Index
NAME
probe::netfilter.arp.out - - Called for each outgoing ARP packet
SYNOPSIS
netfilter.arp.out
VALUES
ar_tip
-
Ethernet+IP only (ar_pro==0x800): target IP address
ar_sha
-
Ethernet+IP only (ar_pro==0x800): source hardware (MAC) address
data_hex
-
A hexadecimal string representing the packet buffer contents
outdev_name
-
Name of network device packet will be routed to (if known)
ar_pln
-
Length of protocol address
ar_sip
-
Ethernet+IP only (ar_pro==0x800): source IP address
nf_drop
-
Constant used to signify a 'drop' verdict
indev_name
-
Name of network device packet was received on (if known)
ar_tha
-
Ethernet+IP only (ar_pro==0x800): target hardware (MAC) address
nf_queue
-
Constant used to signify a 'queue' verdict
nf_repeat
-
Constant used to signify a 'repeat' verdict
length
-
The length of the packet buffer contents, in bytes
nf_accept
-
Constant used to signify an 'accept' verdict
ar_hln
-
Length of hardware address
ar_op
-
ARP opcode (command)
indev
-
Address of net_device representing input device, 0 if unknown
nf_stop
-
Constant used to signify a 'stop' verdict
data_str
-
A string representing the packet buffer contents
ar_hrd
-
Format of hardware address
outdev
-
Address of net_device representing output device, 0 if unknown
ar_pro
-
Format of protocol address
nf_stolen
-
Constant used to signify a 'stolen' verdict
ar_data
-
Address of ARP packet data region (after the header)
arphdr
-
Address of ARP header
pf
-
Protocol family -- always
"arp"
SEE ALSO
tapset::netfilter(3stap)