Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #893 > unrolled thread
| Started by | chcat <vlyamtsev@gmail.com> |
|---|---|
| First post | 2011-12-08 07:24 -0800 |
| Last post | 2011-12-13 16:30 +0000 |
| Articles | 8 — 4 participants |
Back to article view | Back to comp.os.linux.networking
packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-08 07:24 -0800
Re: packet drop notifications -? Richard Kettlewell <rjk@greenend.org.uk> - 2011-12-08 15:43 +0000
Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-08 15:57 +0000
Re: packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-10 05:51 -0800
Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-10 16:54 +0000
Re: packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-11 06:58 -0800
Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-11 15:23 +0000
Re: packet drop notifications -? Jamma Tino Schwarze <jamma-usenet@tisc.de> - 2011-12-13 16:30 +0000
| From | chcat <vlyamtsev@gmail.com> |
|---|---|
| Date | 2011-12-08 07:24 -0800 |
| Subject | packet drop notifications -? |
| Message-ID | <0284c935-4abc-4be4-a36b-20fe51953dba@u32g2000yqe.googlegroups.com> |
Hello, I am looking for the approach to receive notifications in application code when linux firewall drops the packet. Can it be done without changes in kernel code? Thanks....
[toc] | [next] | [standalone]
| From | Richard Kettlewell <rjk@greenend.org.uk> |
|---|---|
| Date | 2011-12-08 15:43 +0000 |
| Message-ID | <874nxbvzl7.fsf@araminta.anjou.terraraq.org.uk> |
| In reply to | #893 |
chcat <vlyamtsev@gmail.com> writes: > I am looking for the approach to receive notifications in application > code when linux firewall drops the packet. > Can it be done without changes in kernel code? > Thanks.... Add a LOG rule before each DROP rule, and then monitor the kernel log output. -- http://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2011-12-08 15:57 +0000 |
| Message-ID | <slrnje1njv.q8l.grahn+nntp@frailea.sa.invalid> |
| In reply to | #894 |
On Thu, 2011-12-08, Richard Kettlewell wrote: > chcat <vlyamtsev@gmail.com> writes: >> I am looking for the approach to receive notifications in application >> code when linux firewall drops the packet. >> Can it be done without changes in kernel code? >> Thanks.... > > Add a LOG rule before each DROP rule, and then monitor the kernel log > output. I seem to recall there are other actions which can be used too ... Depends on what he wants to do. (I once wanted to play a "plonk" sound every time, but never got around to implementing it.) /Jorgen -- // Jorgen Grahn <grahn@ Oo o. . . \X/ snipabacken.se> O o .
[toc] | [prev] | [next] | [standalone]
| From | chcat <vlyamtsev@gmail.com> |
|---|---|
| Date | 2011-12-10 05:51 -0800 |
| Message-ID | <680b75c4-3a11-4b88-8499-5333794ada86@w3g2000vbw.googlegroups.com> |
| In reply to | #894 |
On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote: > chcat <vlyamt...@gmail.com> writes: > > I am looking for the approach to receive notifications in application > > code when linux firewall drops the packet. > > Can it be done without changes in kernel code? > > Thanks.... > > Add a LOG rule before each DROP rule, and then monitor the kernel log > output. > > --http://www.greenend.org.uk/rjk/ Are there other methods that wouldn't require changes of existing RULES ? I am interested more in the terms of programmatic "hooks"... Thanks.
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2011-12-10 16:54 +0000 |
| Message-ID | <slrnje73m7.q8l.grahn+nntp@frailea.sa.invalid> |
| In reply to | #900 |
On Sat, 2011-12-10, chcat wrote:
> On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote:
>> chcat <vlyamt...@gmail.com> writes:
>> > I am looking for the approach to receive notifications in application
>> > code when linux firewall drops the packet.
>> > Can it be done without changes in kernel code?
>> > Thanks....
>>
>> Add a LOG rule before each DROP rule, and then monitor the kernel log
>> output.
> Are there other methods that wouldn't require changes of existing
> RULES ? I am interested more in the terms of programmatic "hooks"...
Why would there be one? iptables(8) says
ACCEPT means to let the packet through. DROP means to drop the
packet on the floor. QUEUE means to pass the packet to
userspace.
They have little reason to add this functionality to DROP, when it's
already available and called QUEUE. (Not counting the many extension
targets, one of which may suit you better, depending on what you want
to do.)
/Jorgen
--
// Jorgen Grahn <grahn@ Oo o. . .
\X/ snipabacken.se> O o .
[toc] | [prev] | [next] | [standalone]
| From | chcat <vlyamtsev@gmail.com> |
|---|---|
| Date | 2011-12-11 06:58 -0800 |
| Message-ID | <5be4fa8c-0d6e-46fe-be39-0d47e25f8804@h18g2000yqg.googlegroups.com> |
| In reply to | #901 |
On Dec 10, 11:54 am, Jorgen Grahn <grahn+n...@snipabacken.se> wrote: > On Sat, 2011-12-10, chcat wrote: > > On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote: > >> chcat <vlyamt...@gmail.com> writes: > >> > I am looking for the approach to receive notifications in application > >> > code when linux firewall drops the packet. > >> > Can it be done without changes in kernel code? > >> > Thanks.... > > >> Add a LOG rule before each DROP rule, and then monitor the kernel log > >> output. > > Are there other methods that wouldn't require changes of existing > > RULES ? I am interested more in the terms of programmatic "hooks"... > > Why would there be one? iptables(8) says > > ACCEPT means to let the packet through. DROP means to drop the > packet on the floor. QUEUE means to pass the packet to > userspace. > > They have little reason to add this functionality to DROP, when it's > already available and called QUEUE. (Not counting the many extension > targets, one of which may suit you better, depending on what you want > to do.) > > /Jorgen > > -- > // Jorgen Grahn <grahn@ Oo o. . . > \X/ snipabacken.se> O o . Sorry if i did not state the problem clearly enough... Iptables firewall is already running on the system. The application in question, or its user cannot change iptables rules. That's up to firewall admin. The application needs approximate count of packet drop by firewall per second. Any suggestions? Thanks in any case.
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2011-12-11 15:23 +0000 |
| Message-ID | <slrnje9imi.q8l.grahn+nntp@frailea.sa.invalid> |
| In reply to | #902 |
On Sun, 2011-12-11, chcat wrote: > On Dec 10, 11:54 am, Jorgen Grahn <grahn+n...@snipabacken.se> wrote: >> On Sat, 2011-12-10, chcat wrote: >> > On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote: >> >> chcat <vlyamt...@gmail.com> writes: >> >> > I am looking for the approach to receive notifications in application >> >> > code when linux firewall drops the packet. >> >> > Can it be done without changes in kernel code? >> >> > Thanks.... >> >> >> Add a LOG rule before each DROP rule, and then monitor the kernel log >> >> output. >> > Are there other methods that wouldn't require changes of existing >> > RULES ? I am interested more in the terms of programmatic "hooks"... >> >> Why would there be one? iptables(8) says >> >> ACCEPT means to let the packet through. DROP means to drop the >> packet on the floor. QUEUE means to pass the packet to >> userspace. >> >> They have little reason to add this functionality to DROP, when it's >> already available and called QUEUE. (Not counting the many extension >> targets, one of which may suit you better, depending on what you want >> to do.) > Sorry if i did not state the problem clearly enough... > Iptables firewall is already running on the system. > The application in question, or its user cannot change iptables rules. > That's up to firewall admin. This sounds like a problem. I think it is unlikely that you'll find a way to do things to the iptables which do not require the cooperation of the admin. > The application needs approximate count of packet drop by firewall per > second. That is a humble wish (little security or privacy impact) but it seems unlikely that you can do anything unless you at least have access to the logs. Note though that I'm not an expert; perhaps someone else can explain the issues better. /Jorgen -- // Jorgen Grahn <grahn@ Oo o. . . \X/ snipabacken.se> O o .
[toc] | [prev] | [next] | [standalone]
| From | Jamma Tino Schwarze <jamma-usenet@tisc.de> |
|---|---|
| Date | 2011-12-13 16:30 +0000 |
| Message-ID | <jc7uj6$o7n$2@easy5.in-chemnitz.de> |
| In reply to | #893 |
Hi chcat, chcat <vlyamtsev@gmail.com> wrote: > I am looking for the approach to receive notifications in application > code when linux firewall drops the packet. You want the notification exactly where? In sending application? Then don't use DROP, use REJECT. It causes ICMP replies to be sent. Jamma. -- "What we nourish flourishes." - "Was wir nähren erblüht." www.tisc.de
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web