Re: packet socket can't steal packets

2 messages, 2 authors, 2002-05-08 · open the first message on its own page

Re: packet socket can't steal packets

From: Carl-Johan Bostorp <hidden>
Date: 1990-01-03 20:25:00

On Tue, May 07, 2002 at 09:02:31PM +0300, Dmitrii Tisnek wrote:
hey, I've been trying to change certain network packet mangling software
such that it would not need a kernel module, and it seems to me that,
unfortunately there's no way to make packet socket "steal" packets it
deliveres to the user mode.
"Divert Sockets for Linux" springs to my mind.. 

http://www.anr.mcnc.org/~divert/index.shtml

---
   Divert sockets enable both IP packet interception and injection on the
   end-hosts as well as on routers. Interception and injection happen at
   the IP layer. The intercepted packets are diverted to sockets in the
   user space, thus they will not be able to reach their destination
   unless they are reinjected by the user space sockets. This allows
   different tricks (e.g., routing and firewall) to be played, outside
   the operating system kernel, in between the packet interception and
   reinjection.
---


-- 
~~~<*>~~~

Web: http://elemental.webservices.se/		   ICQ: 3534707
PGP: 0xA6B5C43B					IRCnet: ctor

~~~<*>~~~

Re: packet socket can't steal packets

From: Chris Friesen <hidden>
Date: 2002-05-08 13:49:53

Carl-Johan Bostorp wrote:
On Tue, May 07, 2002 at 09:02:31PM +0300, Dmitrii Tisnek wrote:
quoted
hey, I've been trying to change certain network packet mangling software
such that it would not need a kernel module, and it seems to me that,
unfortunately there's no way to make packet socket "steal" packets it
deliveres to the user mode.
"Divert Sockets for Linux" springs to my mind..

http://www.anr.mcnc.org/~divert/index.shtml
Except that the original poster is using the 2.4 kernel, for which divert
sockets do not work.

For 2.4 the netfilter module is cleanest, followed by netfilter QUEUE to
userspace (although this will give a performance hit).

When I had to move from 2.2 with divert sockets to 2.4, I used a netfilter
module with commandline parameters to pass in arguments.

Chris

-- 
Chris Friesen                    | MailStop: 043/33/F10  
Nortel Networks                  | work: (613) 765-0557
3500 Carling Avenue              | fax:  (613) 765-2986
Nepean, ON K2H 8E9 Canada        | email: cfriesen@nortelnetworks.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help