> On 2010/09/20 11:10, Henning Brauer wrote: > > oh and when the snaplen is too small i > > don't do the rewrite and pass out the packet unmodified... not sure > > what else we could do but dropping, which would be inconsistent with > > other pcap stuff. > > oh that's wierd indeed. would it be totally insane to print both the > natted and original addresses? then it would be clear that it's been > truncated.
you mean a complete protocol break for pflog? naw, you can do this with henning's new stuff. log the packet twice.
