trafshow and IPFW

Nikos Vassiliadis nvass at teledomenet.gr
Tue Oct 23 06:39:19 PDT 2007


On Saturday 20 October 2007 15:11:48 Grant Peel wrote:
> Hi all,
>
> If I write a rule to block irc ports (6669), and I see them being
> blocked in ipfw, will I still see the connection attemps in trafshow?

You seem to ask, yet I believe you already know the answer :)

Is trafshow using BPF? I took a peek at the project's home page
and it seems that it does so.

Anyway, if that's the case, yes, will see the connection attempts
'cause BPF is hooked on your card's link layer and sees every-
thing that's coming in and going out. That's everything, regard-
less relevance with the upper layers(IP and above).

HTH

Nikos


More information about the freebsd-questions mailing list