probe::netfilter.ip.forward(3stap) — Linux manual page

NAME | SYNOPSIS | VALUES | SEE ALSO | COLOPHON

PROBE::NETFILTER.I(3stap)   Networking Tapset   PROBE::NETFILTER.I(3stap)

NAME         top

       probe::netfilter.ip.forward - Called on an incoming IP packet
       addressed to some other computer

SYNOPSIS         top

       netfilter.ip.forward

VALUES         top

       sport
           TCP or UDP source port (ipv4 only)

       syn
           TCP SYN flag (if protocol is TCP; ipv4 only)

       psh
           TCP PSH flag (if protocol is TCP; ipv4 only)

       iphdr
           Address of IP header

       nf_stolen
           Constant used to signify a 'stolen' verdict

       length
           The length of the packet buffer contents, in bytes

       nf_repeat
           Constant used to signify a 'repeat' verdict

       indev
           Address of net_device representing input device, 0 if unknown

       outdev
           Address of net_device representing output device, 0 if unknown

       urg
           TCP URG flag (if protocol is TCP; ipv4 only)

       ack
           TCP ACK flag (if protocol is TCP; ipv4 only)

       fin
           TCP FIN flag (if protocol is TCP; ipv4 only)

       indev_name
           Name of network device packet was received on (if known)

       saddr
           A string representing the source IP address

       protocol
           Packet protocol from driver (ipv4 only)

       outdev_name
           Name of network device packet will be routed to (if known)

       data_hex
           A hexadecimal string representing the packet buffer contents

       ipproto_tcp
           Constant used to signify that the packet protocol is TCP

       family
           IP address family

       nf_drop
           Constant used to signify a 'drop' verdict

       pf
           Protocol family -- either “ipv4” or “ipv6”

       nf_stop
           Constant used to signify a 'stop' verdict

       nf_accept
           Constant used to signify an 'accept' verdict

       daddr
           A string representing the destination IP address

       nf_queue
           Constant used to signify a 'queue' verdict

       ipproto_udp
           Constant used to signify that the packet protocol is UDP

       data_str
           A string representing the packet buffer contents

       dport
           TCP or UDP destination port (ipv4 only)

       rst
           TCP RST flag (if protocol is TCP; ipv4 only)

SEE ALSO         top

       tapset::netfilter(3stap)

COLOPHON         top

       This page is part of the systemtap (a tracing and live-system
       analysis tool) project.  Information about the project can be
       found at ⟨https://sourceware.org/systemtap/⟩.  If you have a bug
       report for this manual page, send it to systemtap@sourceware.org.
       This page was obtained from the project's upstream Git repository
       ⟨git://sourceware.org/git/systemtap.git⟩ on 2026-05-24.  (At that
       time, the date of the most recent commit that was found in the
       repository was 2026-05-24.)  If you discover any rendering
       problems in this HTML version of the page, or you believe there is
       a better or more up-to-date source for the page, or you have
       corrections or improvements to the information in this COLOPHON
       (which is not part of the original manual page), send a mail to
       man-pages@man7.org

SystemTap Tapset Reference       May 2026       PROBE::NETFILTER.I(3stap)

Pages that refer to this page: tapset::netfilter(3stap)