Hi,

I have a netflow v9 feed to nfacctd from a juniper router (JUNOS 9.6R2.11), using a service pic. According to a packet capture, records include ingress and egress interface and they seem to be properly defined in the corresponding template. I've tried to use the snmp ifindex numbers in pre_tag_map keys, but they never match. Matching in pre_tag_map with other keys seems to work fine. Any ideas how to debug?

I also noticed that proto and ToS are not available as pre_tag_map keys. Any particular reason for that? DSCP matching would be handy in my case.

On a somewhat different note: the particular juniper can also export ipv6 flows, using a different template. I've noticed it includes an IP_PROTOCOL_VERSION (60) field in this template. If we send the ipv6 feed to the same instance of nfacctd which receives the ipv4 feed, how can we tell apart ipv6 from ipv4 traffic if we're doing AS aggregation? It would be handy to have an ip_proto aggregation primitive, or at least to be able to match by 'IPVersion' in a pre_tag_map.

Cheers,
Z.

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to