Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

tcpdump can see traffic fine without an IP on an interface (how much traffic the interface has traffic without one is another question)

pflog interface is not a "real" interface, there's no point in putting an IP address on it



Oh, pflog interfaces are a special device that's known by tcpdump. Interesting.


Yes, kinda.

I'm not sure if tcpdump knows exactly that it's a pflog interface but tcpdump knows how to decode the wire format which traverses the pflog interface.

It's a bit of a weird thing, using a network device for logging information like this, but it works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: