PROBE::NETFILTER\&.I
Section: Networking Tapset (3stap)
Updated: November 2020
Page Index
NAME
probe::netfilter.ip.local_in - Called on an incoming IP packet addressed to the local computer
SYNOPSIS
netfilter.ip.local_in
VALUES
rst
-
TCP RST flag (if protocol is TCP; ipv4 only)
iphdr
-
Address of IP header
indev
-
Address of net_device representing input device, 0 if unknown
nf_stop
-
Constant used to signify a 'stop' verdict
protocol
-
Packet protocol from driver (ipv4 only)
saddr
-
A string representing the source IP address
data_str
-
A string representing the packet buffer contents
ack
-
TCP ACK flag (if protocol is TCP; ipv4 only)
ipproto_udp
-
Constant used to signify that the packet protocol is UDP
daddr
-
A string representing the destination IP address
outdev
-
Address of net_device representing output device, 0 if unknown
pf
-
Protocol family -- either
"ipv4"
or
"ipv6"
nf_stolen
-
Constant used to signify a 'stolen' verdict
data_hex
-
A hexadecimal string representing the packet buffer contents
sport
-
TCP or UDP source port (ipv4 only)
syn
-
TCP SYN flag (if protocol is TCP; ipv4 only)
outdev_name
-
Name of network device packet will be routed to (if known)
dport
-
TCP or UDP destination port (ipv4 only)
indev_name
-
Name of network device packet was received on (if known)
ipproto_tcp
-
Constant used to signify that the packet protocol is TCP
urg
-
TCP URG flag (if protocol is TCP; ipv4 only)
family
-
IP address family
fin
-
TCP FIN flag (if protocol is TCP; ipv4 only)
nf_drop
-
Constant used to signify a 'drop' verdict
nf_accept
-
Constant used to signify an 'accept' verdict
psh
-
TCP PSH flag (if protocol is TCP; ipv4 only)
nf_queue
-
Constant used to signify a 'queue' verdict
length
-
The length of the packet buffer contents, in bytes
nf_repeat
-
Constant used to signify a 'repeat' verdict
SEE ALSO
tapset::netfilter(3stap)