GRE tunnel traffic is leaked to underlay interface
GRE traffic can't be detected in underlay interface
ESP(ipsec) traffic can't be decoded in underlay interface
decode failure should be recorded in debug log
NFLOG
for now, nflog engine is started per interface per direction which will waste resources. use --nflog-prefix with convention direction_interface in iptables to distinguish direction and interface with same nflog group like below:
Common issue
NFLOG
for now, nflog engine is started per interface per direction which will waste resources. use
--nflog-prefix
with conventiondirection_interface
in iptables to distinguish direction and interface with same nflog group like below:duration is not accurate
Libpcap
Afpkt