- called for each outgoing arp packet
netfilter.arp.out
ar_tip
Ethernet+IP only (ar_pro==0x800): target IP address
ar_hrd
Format of hardware address
arphdr
Address of ARP header
nf_accept
Constant used to signify an 'accept' verdict
pf
Protocol family -- always “arp”
nf_stolen
Constant used to signify a 'stolen' verdict
length
The length of the packet buffer contents, in bytes
ar_sha
Ethernet+IP only (ar_pro==0x800): source hardware (MAC) address
outdev_name
Name of network device packet will be routed to (if known)
ar_op
ARP opcode (command)
indev_name
Name of network device packet was received on (if known)
ar_data
Address of ARP packet data region (after the header)
nf_drop
Constant used to signify a 'drop' verdict
ar_pln
Length of protocol address
ar_hln
Length of hardware address
nf_queue
Constant used to signify a 'queue' verdict
outdev
Address of net_device representing output device, 0 if unknown
nf_repeat
Constant used to signify a 'repeat' verdict
indev
Address of net_device representing input device, 0 if unknown
ar_sip
Ethernet+IP only (ar_pro==0x800): source IP address
ar_tha
Ethernet+IP only (ar_pro==0x800): target hardware (MAC) address
ar_pro
Format of protocol address
nf_stop
Constant used to signify a 'stop' verdict