sven falempin <sven.falempin <at> gmail.com> writes: > > The manual say the information is extracted from the state table. > So you should have seen the info. > > First: are you sure the information wasnt in the udp pflow packets ? maybe > the collector was wrong. > Second: man says <<The packet size and thus the maximum number of flows is > controlled by the mtu.>>
The problem is that (I believe) that the pflow packet is not generated until the state expires from pf. In the case of the scp transfer I saw that was not for several days. Meaning I had no accounting/reporting of this data transfer until it ended and the state expired. At which point the entire data transferred during that state's life was counted as if it happened now. -Matt