probe::netfilter.ip.post_routing — Called immediately before an outgoing IP packet leaves the computer
netfilter.ip.post_routing
syn
TCP SYN flag (if protocol is TCP; ipv4 only)
nf_drop
Constant used to signify a 'drop' verdict
nf_queue
Constant used to signify a 'queue' verdict
ipproto_udp
Constant used to signify that the packet protocol is UDP
psh
TCP PSH flag (if protocol is TCP; ipv4 only)
nf_stop
Constant used to signify a 'stop' verdict
indev_name
Name of network device packet was received on (if known)
protocol
Packet protocol from driver (ipv4 only)
dport
TCP or UDP destination port (ipv4 only)
sport
TCP or UDP source port (ipv4 only)
outdev
Address of net_device representing output device, 0 if unknown
saddr
A string representing the source IP address
iphdr
Address of IP header
rst
TCP RST flag (if protocol is TCP; ipv4 only)
urg
TCP URG flag (if protocol is TCP; ipv4 only)
family
IP address family
nf_stolen
Constant used to signify a 'stolen' verdict
nf_accept
Constant used to signify an 'accept' verdict
nf_repeat
Constant used to signify a 'repeat' verdict
fin
TCP FIN flag (if protocol is TCP; ipv4 only)
length
The length of the packet buffer contents, in bytes
ack
TCP ACK flag (if protocol is TCP; ipv4 only)
daddr
A string representing the destination IP address
outdev_name
Name of network device packet will be routed to (if known)
pf
Protocol family -- either “ipv4” or “ipv6”
ipproto_tcp
Constant used to signify that the packet protocol is TCP
indev
Address of net_device representing input device, 0 if unknown