seems to me that actions of the type "tag-mask" are applied to the srcIP and dstIP instead of srcTag and dstTag. Below you'll find an output which is self-explaining, the flow-tools version and the xlate.cfg file.
Thanks for help, Bjoern
[EMAIL PROTECTED] 2004-05-05]# flow-cat ft-v1005.2004-05-05.131528+0000 | flow-xlate -Xcustomer | flow-print | more
srcTag dstTag srcIP dstIP octets packets
0x00020010 0x00010000 0.0.225.4 0.0.72.112 8515 9
0x00010000 0x00010000 0.0.225.3 0.0.32.36 3841 7
0x00020010 0x00010000 0.0.225.4 0.0.72.112 7066 8
0x00020010 0x00010000 0.0.225.4 0.0.124.160 6241 10
0x00020010 0x00010000 0.0.225.4 0.0.72.112 10796 11
0x00020010 0x00010000 0.0.225.4 0.0.72.112 614 5
0x00010000 0x00010000 0.0.225.3 0.0.32.36 4171 7
flow-tools version 0.67: built by [EMAIL PROTECTED] on Wed Jan 7 14:44:08 PHT 2004
[EMAIL PROTECTED] cfg]# cat xlate.cfg
xlate-action apply-customer-mask type tag-mask mask 0x0000FFFF 0x0000FFFF
xlate-definition customer term action apply-customer-mask _______________________________________________ Flow-tools mailing list [EMAIL PROTECTED] http://mailman.splintered.net/mailman/listinfo/flow-tools
