Hi, On Sun, Aug 28, 2011 at 10:23:57AM -0400, Matthew Huff wrote: > Netflow *collection* of flows traversing the NAT-ed interface.
Thanks for clarification. Yes, indeed, that makes more sense (in a way)
and is not that easy to work around.
One could try some VRF tricks (NAT in one VRF, netflow in another VRF,
hardware-loopback from one GigE/VRF-1 to another GigE/VRF-2) on the
same box, but that's not exactly a clean design.
OTOH, I can't see why the hardware couldn't properly age out NAT
entries, and then send a NDE record when the NAT entry expires... after
all, it will have to do NAT state table entry cleanup anyway. (But to
get Cisco to work on that, you might have to offer to buy another 500
boxes...)
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgpoUXulwhA4g.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
