Using netgraph for filtering/modifing packets

James Housley jim at Thehousleys.net
Mon Jun 14 14:50:03 GMT 2004


For testing of a product I would like to be able to modify or even drop
packets based on their content.  What I have in mind is forcing the
packets through a firewall that would redirect all packet to a netgraph
node that would either pass unchanged, drop or change the contents to
assist in testing some corner cases in the code.

1) is this something doable with netgraph, I believe it is.

2) what might be a good place to start?  Have done some searching, but
haven't found any example code I thought I could start from.

Thanks,
Jim

-- 
/"\   ASCII Ribbon Campaign  .
\ / - NO HTML/RTF in e-mail  .
   X  - NO Word docs in e-mail .
/ \ -----------------------------------------------------------------
jeh at FreeBSD.org      http://www.FreeBSD.org     The Power to Serve
jim at TheHousleys.Net  http://www.TheHousleys.net
---------------------------------------------------------------------
Your mouse has moved.
Windows NT must be restarted for the change to take effect!

Reboot now?  [OK]
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3228 bytes
Desc: S/MIME Cryptographic Signature
Url : http://lists.freebsd.org/pipermail/freebsd-net/attachments/20040614/d54273de/smime.bin


More information about the freebsd-net mailing list