I want to log traffic details for every packet using IPTABLES on mirrored traffic coming from a switch on my interface em4 with -j LOG
option. I saw a similar scenario here.
em4 is in promisc mode.
I'm using the following commands but the rule is not getting hit and I cannot see logs in /var/log/messages
tunctl -u root
brctl addbr br0
brctl addif br0 em4
brctl addif br0 tap0
brctl setfd br0 0
brctl stp br0 off
ifconfig br0 up
ifconfig eth0 up 0.0.0.0
ifconfig tap0 up 0.0.0.0
echo 0 > /sys/class/net/br0/bridge/ageing_time
echo 1 > /sys/devices/virtual/net/br0/bridge/nf_call_iptables
iptables -F
iptables -A PREROUTING -t raw -j LOG