From owner-freebsd-net@FreeBSD.ORG Tue Aug 5 16:54:16 2003 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0B15B37B401 for ; Tue, 5 Aug 2003 16:54:16 -0700 (PDT) Received: from topaz.ad1810.com (topaz.ad1810.com [212.204.230.141]) by mx1.FreeBSD.org (Postfix) with ESMTP id 516D843FB1 for ; Tue, 5 Aug 2003 16:54:15 -0700 (PDT) (envelope-from edwin@mavetju.org) Received: from localhost ([127.0.0.1] helo=k7.mavetju ident=edwin) by topaz.ad1810.com with esmtp (Exim 3.35 #1 (Debian)) id 19kBd7-0000ST-00 for ; Wed, 06 Aug 2003 01:54:14 +0200 Received: by k7.mavetju (Postfix, from userid 1001) id A63796A7101; Wed, 6 Aug 2003 09:54:11 +1000 (EST) Date: Wed, 6 Aug 2003 09:54:11 +1000 From: Edwin Groothuis To: freebsd-net@freebsd.org Message-ID: <20030805235411.GA558@k7.mavetju> References: <20030805133922.GA7713@k7.mavetju> <20030805143100.GA52099@pit.databus.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20030805143100.GA52099@pit.databus.com> User-Agent: Mutt/1.4.1i Subject: Re: bpf, ipfw and before-and-after X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 05 Aug 2003 23:54:16 -0000 On Tue, Aug 05, 2003 at 10:31:01AM -0400, Barney Wolff wrote: > On Tue, Aug 05, 2003 at 11:39:23PM +1000, Edwin Groothuis wrote: > > > > Now my question to you guys is, does what I want or what I describe > > here make a little bit sense? Or am I totally going the wrong way? > > Or has this topic already been discussed multiple times and decided > > not to do it? Maybe there is somebody thinks this is a cool thing > > and wants to help me with adding it to the system? > > Seems to me that with ipfw logging and tcpdump packet selection this > is largely a non-issue. We should be wary of adding complexity to > what's already at the limits of human comprehension. Could you explain that first line a little bit more verbose? About the second one, given the fact that I could find out how it works (more or less) and where to add the statements, makes me think that despite the complexity of the thing being achieved, the implementation in the code is pretty neat and structured. Edwin -- Edwin Groothuis edwin@freebsd.org