Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #893 > unrolled thread

packet drop notifications -?

Started bychcat <vlyamtsev@gmail.com>
First post2011-12-08 07:24 -0800
Last post2011-12-13 16:30 +0000
Articles 8 — 4 participants

Back to article view | Back to comp.os.linux.networking


Contents

  packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-08 07:24 -0800
    Re: packet drop notifications -? Richard Kettlewell <rjk@greenend.org.uk> - 2011-12-08 15:43 +0000
      Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-08 15:57 +0000
      Re: packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-10 05:51 -0800
        Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-10 16:54 +0000
          Re: packet drop notifications -? chcat <vlyamtsev@gmail.com> - 2011-12-11 06:58 -0800
            Re: packet drop notifications -? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-12-11 15:23 +0000
    Re: packet drop notifications -? Jamma Tino Schwarze <jamma-usenet@tisc.de> - 2011-12-13 16:30 +0000

#893 — packet drop notifications -?

Fromchcat <vlyamtsev@gmail.com>
Date2011-12-08 07:24 -0800
Subjectpacket drop notifications -?
Message-ID<0284c935-4abc-4be4-a36b-20fe51953dba@u32g2000yqe.googlegroups.com>
Hello,
I am looking for the approach to receive notifications in application
code when linux firewall drops the packet.
Can it be done without changes in kernel code?
Thanks....

[toc] | [next] | [standalone]


#894

FromRichard Kettlewell <rjk@greenend.org.uk>
Date2011-12-08 15:43 +0000
Message-ID<874nxbvzl7.fsf@araminta.anjou.terraraq.org.uk>
In reply to#893
chcat <vlyamtsev@gmail.com> writes:
> I am looking for the approach to receive notifications in application
> code when linux firewall drops the packet.
> Can it be done without changes in kernel code?
> Thanks....

Add a LOG rule before each DROP rule, and then monitor the kernel log
output.

-- 
http://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#895

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2011-12-08 15:57 +0000
Message-ID<slrnje1njv.q8l.grahn+nntp@frailea.sa.invalid>
In reply to#894
On Thu, 2011-12-08, Richard Kettlewell wrote:
> chcat <vlyamtsev@gmail.com> writes:
>> I am looking for the approach to receive notifications in application
>> code when linux firewall drops the packet.
>> Can it be done without changes in kernel code?
>> Thanks....
>
> Add a LOG rule before each DROP rule, and then monitor the kernel log
> output.

I seem to recall there are other actions which can be used too ...
Depends on what he wants to do.

(I once wanted to play a "plonk" sound every time, but never got
around to implementing it.)

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#900

Fromchcat <vlyamtsev@gmail.com>
Date2011-12-10 05:51 -0800
Message-ID<680b75c4-3a11-4b88-8499-5333794ada86@w3g2000vbw.googlegroups.com>
In reply to#894
On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote:
> chcat <vlyamt...@gmail.com> writes:
> > I am looking for the approach to receive notifications in application
> > code when linux firewall drops the packet.
> > Can it be done without changes in kernel code?
> > Thanks....
>
> Add a LOG rule before each DROP rule, and then monitor the kernel log
> output.
>
> --http://www.greenend.org.uk/rjk/

Are there other methods that wouldn't require changes of existing
RULES ? I am interested more in the terms of programmatic "hooks"...
Thanks.

[toc] | [prev] | [next] | [standalone]


#901

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2011-12-10 16:54 +0000
Message-ID<slrnje73m7.q8l.grahn+nntp@frailea.sa.invalid>
In reply to#900
On Sat, 2011-12-10, chcat wrote:
> On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote:
>> chcat <vlyamt...@gmail.com> writes:
>> > I am looking for the approach to receive notifications in application
>> > code when linux firewall drops the packet.
>> > Can it be done without changes in kernel code?
>> > Thanks....
>>
>> Add a LOG rule before each DROP rule, and then monitor the kernel log
>> output.

> Are there other methods that wouldn't require changes of existing
> RULES ? I am interested more in the terms of programmatic "hooks"...

Why would there be one? iptables(8) says

       ACCEPT means to let the packet through.  DROP means to drop the
       packet on the floor.  QUEUE means to pass the packet to
       userspace.

They have little reason to add this functionality to DROP, when it's
already available and called QUEUE. (Not counting the many extension
targets, one of which may suit you better, depending on what you want
to do.)

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#902

Fromchcat <vlyamtsev@gmail.com>
Date2011-12-11 06:58 -0800
Message-ID<5be4fa8c-0d6e-46fe-be39-0d47e25f8804@h18g2000yqg.googlegroups.com>
In reply to#901
On Dec 10, 11:54 am, Jorgen Grahn <grahn+n...@snipabacken.se> wrote:
> On Sat, 2011-12-10, chcat wrote:
> > On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote:
> >> chcat <vlyamt...@gmail.com> writes:
> >> > I am looking for the approach to receive notifications in application
> >> > code when linux firewall drops the packet.
> >> > Can it be done without changes in kernel code?
> >> > Thanks....
>
> >> Add a LOG rule before each DROP rule, and then monitor the kernel log
> >> output.
> > Are there other methods that wouldn't require changes of existing
> > RULES ? I am interested more in the terms of programmatic "hooks"...
>
> Why would there be one? iptables(8) says
>
>        ACCEPT means to let the packet through.  DROP means to drop the
>        packet on the floor.  QUEUE means to pass the packet to
>        userspace.
>
> They have little reason to add this functionality to DROP, when it's
> already available and called QUEUE. (Not counting the many extension
> targets, one of which may suit you better, depending on what you want
> to do.)
>
> /Jorgen
>
> --
>   // Jorgen Grahn <grahn@  Oo  o.   .     .
> \X/     snipabacken.se>   O  o   .

Sorry if i did not state the problem clearly enough...
Iptables firewall is already running on the system.
The application in question, or its user cannot change iptables rules.
That's up to firewall admin.
The application needs approximate count of packet drop by firewall per
second.
 Any suggestions?
Thanks in any case.

[toc] | [prev] | [next] | [standalone]


#904

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2011-12-11 15:23 +0000
Message-ID<slrnje9imi.q8l.grahn+nntp@frailea.sa.invalid>
In reply to#902
On Sun, 2011-12-11, chcat wrote:
> On Dec 10, 11:54 am, Jorgen Grahn <grahn+n...@snipabacken.se> wrote:
>> On Sat, 2011-12-10, chcat wrote:
>> > On Dec 8, 10:43 am, Richard Kettlewell <r...@greenend.org.uk> wrote:
>> >> chcat <vlyamt...@gmail.com> writes:
>> >> > I am looking for the approach to receive notifications in application
>> >> > code when linux firewall drops the packet.
>> >> > Can it be done without changes in kernel code?
>> >> > Thanks....
>>
>> >> Add a LOG rule before each DROP rule, and then monitor the kernel log
>> >> output.
>> > Are there other methods that wouldn't require changes of existing
>> > RULES ? I am interested more in the terms of programmatic "hooks"...
>>
>> Why would there be one? iptables(8) says
>>
>>        ACCEPT means to let the packet through.  DROP means to drop the
>>        packet on the floor.  QUEUE means to pass the packet to
>>        userspace.
>>
>> They have little reason to add this functionality to DROP, when it's
>> already available and called QUEUE. (Not counting the many extension
>> targets, one of which may suit you better, depending on what you want
>> to do.)

> Sorry if i did not state the problem clearly enough...
> Iptables firewall is already running on the system.
> The application in question, or its user cannot change iptables rules.
> That's up to firewall admin.

This sounds like a problem. I think it is unlikely that you'll find a
way to do things to the iptables which do not require the cooperation
of the admin.

> The application needs approximate count of packet drop by firewall per
> second.

That is a humble wish (little security or privacy impact) but it seems
unlikely that you can do anything unless you at least have access to
the logs.

Note though that I'm not an expert; perhaps someone else can explain
the issues better.

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#907

FromJamma Tino Schwarze <jamma-usenet@tisc.de>
Date2011-12-13 16:30 +0000
Message-ID<jc7uj6$o7n$2@easy5.in-chemnitz.de>
In reply to#893
Hi chcat,

chcat <vlyamtsev@gmail.com> wrote:

> I am looking for the approach to receive notifications in application
> code when linux firewall drops the packet.

You want the notification exactly where? In sending application? Then
don't use DROP, use REJECT. It causes ICMP replies to be sent.

Jamma.

-- 
"What we nourish flourishes." - "Was wir nähren erblüht."

www.tisc.de

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web