In the beginning of the year I had to change on out Cat 6500
from netflow v5 to v9 just get IPv6 into my flows.

As I have a profile that especially deals with ICMP traffic
and shows type & codes of ICMP packets, I was surprised,
that ICMP type & code (which are stored in the "destination port")
are now swapped in this two-byte field.

So my graphs have now some interesting types ...

Question: "feature" of my cat 6500 or bug in nfdump?

-- 
Dipl.-Phys. Jens Hektor, Netzbetrieb
RWTH Aachen University, Center for Computing and Communication
Room 2.04, Wendlingweg 10, 52074 Aachen (Germany)
Phone: +49 241 80 29206 - Fax: +49 241 80 22100
http://www.rz.rwth-aachen.de - hek...@rz.rwth-aachen.de

Attachment: smime.p7s
Description: S/MIME Kryptografische Unterschrift

------------------------------------------------------------------------------
This SF.net email is sponsored by Windows:

Build for Windows Store.

http://p.sf.net/sfu/windows-dev2dev
_______________________________________________
Nfsen-discuss mailing list
Nfsen-discuss@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss

Reply via email to