Ben Hicks wrote:
From
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6555/ps6601/prod_white_paper0900aecd80406232.html
-The NetFlow cache is constantly filling with flows and software in the
router or switch is searching the cache for flows that have terminated
or expired and these flows are exported to the NetFlow collector server.
Flows are terminated when the network communication has ended (ie: a
packet contains the TCP FIN flag). The following steps are used to
Ok, this appears to be the key.
I was under the impression that the 6500 PFC/DFC were not TCP-flag
aware, however as you say, testing indicates they are.
Thanks all.
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/