From: Liping Zhang
After NF_LOG_XXX is exposed to the userspace, we can set log flags to
log more things. The following iptables rule:
# iptables -A OUTPUT -j LOG --log-tcp-sequence --log-tcp-options \
--log-ip-options --log-uid --log-macdecode
is equal to the following nft rule:
# nft add
On Sun, Sep 25, 2016 at 05:06:58PM +0800, Liping Zhang wrote:
> From: Liping Zhang
>
> After NF_LOG_XXX is exposed to the userspace, we can set log flags to
> log more things. The following iptables rule:
> # iptables -A OUTPUT -j LOG --log-tcp-sequence --log-tcp-options \
> --log-ip-options
2016-11-15 6:21 GMT+08:00 Pablo Neira Ayuso :
> On Sun, Sep 25, 2016 at 05:06:58PM +0800, Liping Zhang wrote:
>> From: Liping Zhang
>>
>> After NF_LOG_XXX is exposed to the userspace, we can set log flags to
>> log more things. The following iptables rule:
>> # iptables -A OUTPUT -j LOG --log-tc