On Wednesday 2010-08-04 18:39, Nicolas de Pesloüan wrote: >>> I'm not 100% sure it is completely outside though. For instance, >>> if you do tcdump on a bridge device (as opposed to the corresponding >>> physical participant interface), isn't that after ingress ebtales >>> processing, but before egress? IE is in the graph somewhere. >> >> Huh, all once investigated already. See >> http://jengelh.medozas.de/images/nf-packet-flow.png for where >> in/egress happen to be. :) > > Nice work! > > May be just missing other netif_receive_skb() magic, like bonding for example. Well, bonding is not really part of Netfilter. Then again, neither is ingress/xfrm ;-) -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html