Refer to shorewall(8) for packet mark display

This commit is contained in:
Tom Eastep 2009-06-17 13:40:02 -07:00
parent f11efc7319
commit d21c927d29

View File

@ -51,7 +51,11 @@
stored in the <emphasis>skb</emphasis> (socket buffer) structure used by
the Linux kernel to track packets; the mark value is not part of the
packet itself and cannot be seen with <command>tcpdump</command>,
<command>ethereal</command> or any other packet sniffing program.</para>
<command>ethereal</command> or any other packet sniffing program. They can
be seen in an iptables/ip6tables trace -- see the
<command>iptrace</command> command in <ulink
url="manpages/shorewall.html">shorewal</ulink>(8) and <ulink
url="manpages6/shorewall6.html">shorewall6</ulink>(8).</para>
<para>Each active connection (even those that are not yet in ESTABLISHED
state) has a mark value that is distinct from the packet marks. Connection