Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 23 Oct 2007 16:41:43 +0300
From:      Nikos Vassiliadis <nvass@teledomenet.gr>
To:        freebsd-questions@freebsd.org, Grant Peel <gpeel@thenetnow.com>
Subject:   Re: trafshow and IPFW
Message-ID:  <200710231641.44609.nvass@teledomenet.gr>
In-Reply-To: <004f01c81312$640be7a0$6501a8c0@GRANT>
References:  <004f01c81312$640be7a0$6501a8c0@GRANT>

next in thread | previous in thread | raw e-mail | index | archive | help
On Saturday 20 October 2007 15:11:48 Grant Peel wrote:
> Hi all,
>
> If I write a rule to block irc ports (6669), and I see them being
> blocked in ipfw, will I still see the connection attemps in trafshow?

You seem to ask, yet I believe you already know the answer :)

Is trafshow using BPF? I took a peek at the project's home page
and it seems that it does so.

Anyway, if that's the case, yes, will see the connection attempts
'cause BPF is hooked on your card's link layer and sees every-
thing that's coming in and going out. That's everything, regard-
less relevance with the upper layers(IP and above).

HTH

Nikos



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200710231641.44609.nvass>