probe::netfilter.ip.forward — Called on an incoming IP packet addressed to some other computer
netfilter.ip.forward
synTCP SYN flag (if protocol is TCP; ipv4 only)
dportTCP or UDP destination port (ipv4 only)
lengthThe length of the packet buffer contents, in bytes
nf_acceptConstant used to signify an 'accept' verdict
nf_dropConstant used to signify a 'drop' verdict
daddrA string representing the destination IP address
nf_stolenConstant used to signify a 'stolen' verdict
iphdrAddress of IP header
nf_stopConstant used to signify a 'stop' verdict
pshTCP PSH flag (if protocol is TCP; ipv4 only)
indev_nameName of network device packet was received on (if known)
familyIP address family
saddrA string representing the source IP address
rstTCP RST flag (if protocol is TCP; ipv4 only)
outdev_nameName of network device packet will be routed to (if known)
urgTCP URG flag (if protocol is TCP; ipv4 only)
outdevAddress of net_device representing output device, 0 if unknown
sportTCP or UDP source port (ipv4 only)
ipproto_tcpConstant used to signify that the packet protocol is TCP
nf_queueConstant used to signify a 'queue' verdict
data_strA string representing the packet buffer contents
ackTCP ACK flag (if protocol is TCP; ipv4 only)
ipproto_udpConstant used to signify that the packet protocol is UDP
protocolPacket protocol from driver (ipv4 only)
finTCP FIN flag (if protocol is TCP; ipv4 only)
nf_repeatConstant used to signify a 'repeat' verdict
data_hexA hexadecimal string representing the packet buffer contents
pfProtocol family -- either “ipv4” or “ipv6”
indevAddress of net_device representing input device, 0 if unknown