sven falempin <sven.falempin <at> gmail.com> writes:

> 
> The manual say the information is extracted from the state table.
> So you should have seen the info.
> 
> First: are you sure the information wasnt in the udp pflow packets ? maybe
> the collector was wrong.
> Second: man says <<The packet size and thus the maximum number of flows is
> controlled by the mtu.>>

The problem is that (I believe) that the pflow packet is not generated until
the state expires from pf. In the case of the scp transfer I saw that was not
for several days. Meaning I had no accounting/reporting of this data
transfer until it ended and the state expired. At which point the entire
data transferred during that state's life was counted as if it happened now.

-Matt

Reply via email to