DOKK / manpages / debian 12 / systemtap-doc / probe::netfilter.ip.pre_routing.3stap.en
PROBE::NETFILTER.I(3stap) Networking Tapset PROBE::NETFILTER.I(3stap)

probe::netfilter.ip.pre_routing - Called before an IP packet is routed

netfilter.ip.pre_routing 

data_str

A string representing the packet buffer contents

nf_queue

Constant used to signify a 'queue' verdict

length

The length of the packet buffer contents, in bytes

fin

TCP FIN flag (if protocol is TCP; ipv4 only)

nf_drop

Constant used to signify a 'drop' verdict

indev_name

Name of network device packet was received on (if known)

saddr

A string representing the source IP address

pf

Protocol family - either 'ipv4' or 'ipv6'

syn

TCP SYN flag (if protocol is TCP; ipv4 only)

nf_stop

Constant used to signify a 'stop' verdict

daddr

A string representing the destination IP address

psh

TCP PSH flag (if protocol is TCP; ipv4 only)

outdev_name

Name of network device packet will be routed to (if known)

protocol

Packet protocol from driver (ipv4 only)

urg

TCP URG flag (if protocol is TCP; ipv4 only)

ack

TCP ACK flag (if protocol is TCP; ipv4 only)

rst

TCP RST flag (if protocol is TCP; ipv4 only)

family

IP address family

dport

TCP or UDP destination port (ipv4 only)

iphdr

Address of IP header

ipproto_tcp

Constant used to signify that the packet protocol is TCP

nf_repeat

Constant used to signify a 'repeat' verdict

ipproto_udp

Constant used to signify that the packet protocol is UDP

nf_stolen

Constant used to signify a 'stolen' verdict

outdev

Address of net_device representing output device, 0 if unknown

sport

TCP or UDP source port (ipv4 only)

nf_accept

Constant used to signify an 'accept' verdict

indev

Address of net_device representing input device, 0 if unknown

data_hex

A hexadecimal string representing the packet buffer contents

tapset::netfilter(3stap)

November 2022 SystemTap Tapset Reference