Iptables and libpcap

I have a rule configured to remove udp / tcp packages with the corresponding lines. however, my program that captures a package using libpcap can still see this package.

Why is this / what should the iptable rules be for removing packages before it sees libpcap?

In any case, it is possible, in addition to the iptables rules, that you need to remove this package before libpcap / tcpdump sees it?

+3
source share
3 answers

Yes, libpcap sees all the packages. . They are captured before being filtered.

+7
source

? , , libpcap .

* , linux *

EDIT: Libpcap - . linux , netfilter.

0

libpcap netfilter, netfilter - , , , ​​ . ? , libpcap netfilter, iptables. , , netfilter, . , libpcap .

-2

Source: https://habr.com/ru/post/1707764/


All Articles