2003-09-24 02:24:21 UTC
This would work great for a bridge firewall.
Has anyone done a work up on how the parse works?
This is an example of my log.
kernel: IN=br0 OUT= PHYSIN=eth1 MAC=00:0a:01:99:4d:ee:00:07:50:ef:32:a8:08:00 SRC=127.0.0.1 DST=127.0.0.1 LEN=92 TOS=0x00 PREC=0x00 TTL=113 ID=3533 PROTO=ICMP TYPE=8 CODE=0 ID=512 SEQ=44249
kernel: IN=br0 OUT= PHYSIN=eth1 MAC=00:0a:01:99:4d:ee:00:07:50:ef:32:a8:08:00 SRC=127.0.0.1 DST=127.0.0.1 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=3542 DF PROTO=TCP SPT=4699 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
kernel: IN=br0 OUT= PHYSIN=eth1 MAC=00:0a:01:99:4d:ee:00:07:50:ef:32:a8:08:00 SRC=219.139.238.35 DST=127.0.0.1 LEN=78 TOS=0x00 PREC=0x00 TTL=110 ID=23708 PROTO=UDP SPT=21033 DPT=137 LEN=58
Can anyone help me out with it?