The ulog extension of iptables can be programmed to bunch headers together and to pass them on to fprobe via a Netlink socket. The following rule must be in place for this mechanism to function:
When this rule is not active, fprobe (discussed next) will not generate any log data.